DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Thinkinai
Thinkinai deepchat |
|
CPEs | cpe:2.3:a:thinkinai:deepchat:0.3.0:*:*:*:*:*:*:* | |
Vendors & Products |
Thinkinai
Thinkinai deepchat |
Tue, 19 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 19 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1. | |
Title | DeepChat One-click Remote Code Execution through Custom URL Handling | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-19T20:49:59.391Z
Reserved: 2025-08-14T22:31:17.683Z
Link: CVE-2025-55733

Updated: 2025-08-19T20:49:30.413Z

Status : Analyzed
Published: 2025-08-19T19:15:37.260
Modified: 2025-09-17T17:58:46.877
Link: CVE-2025-55733

No data.