CVE-2025-47777

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-47777
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47777.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47777
Aliases
  • GHSA-mr8w-mmvv-6hq8
Published
2025-05-14T16:15:28Z
Modified
2025-05-17T14:29:18.453314Z
Summary
[none]
Details

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched releases, particularly those interacting with untrusted chatbots or pasting external content, are affected. Version 0.11.1 contains a patch for the issue.

References

Affected packages

Git / github.com/nanbingxyz/5ire

Affected ranges

Type
GIT
Repo
https://github.com/nanbingxyz/5ire
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.10.0
v0.10.1
v0.11.0
v0.7.9
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9