CVE-2025-47777 – 5ire Stored XSS and RCE Vulnerability

The following table lists the changes that have been made to the
CVE-2025-47777 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 14, 2025

    Action Type Old Value New Value
    Added Description 5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to 0.11.1 are vulnerable to stored cross-site scripting in chatbot responses due to insufficient sanitization. This, in turn, can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. All users of 5ire client versions prior to patched releases, particularly those interacting with untrusted chatbots or pasting external content, are affected. Version 0.11.1 contains a patch for the issue.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
    Added CWE CWE-79
    Added CWE CWE-20
    Added Reference https://github.com/nanbingxyz/5ire/commit/56601e012095194a4be0d4cb6da6b5b3cb53dea8
    Added Reference https://github.com/nanbingxyz/5ire/security/advisories/GHSA-mr8w-mmvv-6hq8
    Added Reference https://positive.security/blog/url-open-rce
    Added Reference https://shabarkin.notion.site/1-click-RCE-in-Electron-Applications-501c2e96e7934610979cd3c72e844a22
    Added Reference https://www.electronjs.org/docs/latest/tutorial/security
    Added Reference https://www.youtube.com/watch?v=ROFYhS9E9eU
Share the Post:

Related Posts