Description

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.ts, where the markdown-it-mermaid plugin is initialized with securityLevel: 'loose'. This configuration explicitly permits the rendering of HTML tags within Mermaid diagram nodes. This issue has not been patched at time of publication.

INFO

Published Date :

2025-12-23T22:51:35.848Z

Last Modified :

2026-02-06T19:29:07.289Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-68669 vulnerability.

Vendors Products
5ire
  • 5ire
Nanbingxyz
  • 5ire

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact