DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Aug 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 19 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1. | |
Title | DeepChat One-click Remote Code Execution through Custom URL Handling | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-19T18:26:38.741Z
Updated: 2025-08-19T20:49:59.391Z
Reserved: 2025-08-14T22:31:17.683Z
Link: CVE-2025-55733

Updated: 2025-08-19T20:49:30.413Z

Status : Awaiting Analysis
Published: 2025-08-19T19:15:37.260
Modified: 2025-08-20T14:40:17.713
Link: CVE-2025-55733

No data.