CVE-2025-47777

CRITICAL EPSS 52.3%
Published May 14, 20251y ago · Modified Jun 17, 20261w ago
9.6 CVSS 3.1
Critical
Find Similar
Published May 14, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched releases, particularly those interacting with untrusted chatbots or pasting external content, are affected. Version 0.11.1 contains a patch for the issue.

CVSS Details

Base Score
9.6
Exploitability
2.8
Impact
6.0
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
52.3% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 2

CWE-20 Improper Input Validation Validation
CWE-79 Cross-site Scripting Injection

Affected Products 1

VendorProductVersionRange
5ire5ire* <0.11.1

References 6

  • github.com https://github.com/nanbingxyz/5ire/commit/56601e012095194a4be0d4cb6da6b5b3cb53dea8
    Patch
  • github.com https://github.com/nanbingxyz/5ire/security/advisories/GHSA-mr8w-mmvv-6hq8
    Vendor Advisory
  • positive.security https://positive.security/blog/url-open-rce
    Not Applicable
  • shabarkin.notion.site https://shabarkin.notion.site/1-click-RCE-in-Electron-Applications-501c2e96e7934610979cd3c72e844a22
    Not Applicable
  • electronjs.org https://www.electronjs.org/docs/latest/tutorial/security
    Not Applicable
  • youtube.com https://www.youtube.com/watch?v=ROFYhS9E9eU
    Exploit

Remediation

  • github.com https://github.com/nanbingxyz/5ire/commit/56601e012095194a4be0d4cb6da6b5b3cb53dea8
    Patch