Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-63872 1 Deepseek 2 Deepseek, Deepseek-v3 2025-12-04 6.1 Medium
DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content.
CVE-2025-26210 1 Deepseek 4 Deepseek, Deepseek-r1, Deepseek-v2 and 1 more 2025-09-26 8.8 High
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.