5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2 and prior, an RCE vulnerability exists in useMarkdown.ts, where the markdown-it-mermaid plugin is initialized with securityLevel: 'loose'. This configuration explicitly permits the rendering of HTML tags within Mermaid diagram nodes. This issue has not been patched at time of publication.
References
| Link | Resource |
|---|---|
| https://github.com/nanbingxyz/5ire/blob/c40d05a2b546094789fc727daa5383bb15034442/src/hooks/useMarkdown.ts#L156 | Product |
| https://github.com/nanbingxyz/5ire/releases/tag/v0.15.2 | Release Notes |
| https://github.com/nanbingxyz/5ire/security/advisories/GHSA-5hpf-p8fw-j349 | Exploit Vendor Advisory |
| https://github.com/nanbingxyz/5ire/security/advisories/GHSA-5hpf-p8fw-j349 | Exploit Vendor Advisory |
Configurations
History
07 Jan 2026, 15:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:5ire:5ire:*:*:*:*:*:*:*:* | |
| References | () https://github.com/nanbingxyz/5ire/blob/c40d05a2b546094789fc727daa5383bb15034442/src/hooks/useMarkdown.ts#L156 - Product | |
| References | () https://github.com/nanbingxyz/5ire/releases/tag/v0.15.2 - Release Notes | |
| References | () https://github.com/nanbingxyz/5ire/security/advisories/GHSA-5hpf-p8fw-j349 - Exploit, Vendor Advisory | |
| First Time |
5ire
5ire 5ire |
24 Dec 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nanbingxyz/5ire/security/advisories/GHSA-5hpf-p8fw-j349 - |
23 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 23:15
Updated : 2026-01-07 15:12
NVD link : CVE-2025-68669
Mitre link : CVE-2025-68669
CVE.ORG link : CVE-2025-68669
JSON object : View
Products Affected
5ire
- 5ire
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
