D
eepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
References
| Link | Resource |
|---|---|
| https://deepseek.com | Permissions Required |
| https://hackmd.io/@MrqrFIlhQFi7vUwkqbrXDw/deepseek | Exploit Third Party Advisory |
| https://youtu.be/IgQwy52FVT4 | Exploit |
Configurations
Configuration 1 (hide)
|
History
26 Sep 2025, 13:58
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-03 14:15
Updated : 2025-09-26 13:58
NVD link : CVE-2025-26210
Mitre link : CVE-2025-26210
CVE.ORG link : CVE-2025-26210
JSON object : View
Products Affected
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')