CVE-2026-43900: DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepa...
Added to the CISA Known Exploited Vulnerabilities catalog on 11 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 9.3.
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer...
Required action: Review and patch if applicable to your AI infrastructure.