Junglewise Threat Intelligence

CVE-2026-43900: ThinkInAIXYZ DeepChat XSS via HTML entity encoding in SVG rendering

CVE-2026-43900 · Severity: critical · CVSS 9.3 · Published 2026-05-11

Executive brief

DeepChat is an open-source platform used to integrate and manage various AI models and tools. A security flaw allows attackers to execute malicious code in a user's browser by sending specially crafted SVG images through an AI chat response. If a user interacts with the malicious image, an attacker could steal sensitive session data, access private chat history, or potentially compromise the underlying system.

Technical details

A stored/reflected Cross-Site Scripting (XSS) vulnerability exists in DeepChat's SVG rendering component. The SVGSanitizer (src/main/lib/svgSanitizer.ts) attempts to block 'javascript:' protocols using plain-text regular expressions. However, it fails to account for HTML entity decoding (e.g., 'javascript:') which occurs when the SvgArtifact.vue component uses Vue's v-html directive to insert content into the DOM. An attacker can provide a malicious SVG artifact via a custom LLM provider that bypasses the regex filter but is executed by the browser's rendering engine upon user interaction. This can lead to session hijacking or execution of arbitrary Node.js APIs if the Electron client has sufficient privileges. The issue is fixed in version 1.0.4-beta.1.

Affected products

  • ThinkInAIXYZ DeepChat < v1.0.4-beta.1

Timeline

  • 2026-04-25: advisory: GitHub Security Advisory published
  • 2026-05-11: disclosed: CVE published to NVD

References

Related threats