DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
References
| Link | Resource |
|---|---|
| https://deepseek.com | Permissions Required |
| https://hackmd.io/@MrqrFIlhQFi7vUwkqbrXDw/deepseek | Exploit Third Party Advisory |
| https://youtu.be/IgQwy52FVT4 | Exploit |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-03 14:15
Updated : 2025-09-26 13:58
NVD link : CVE-2025-26210
Mitre link : CVE-2025-26210
CVE.ORG link : CVE-2025-26210
JSON object : View
Products Affected
deepseek
- deepseek-r1
- deepseek-v2
- deepseek-v3
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
