Vulnerability Description
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deepseek | Deepseek-R1 | 1.0 |
| Deepseek | Deepseek-V2 | - |
| Deepseek | Deepseek-V3 | 1.0 |
Related Weaknesses (CWE)
References
- https://deepseek.comPermissions Required
- https://hackmd.io/@MrqrFIlhQFi7vUwkqbrXDw/deepseekExploitThird Party Advisory
- https://youtu.be/IgQwy52FVT4Exploit
FAQ
What is CVE-2025-26210?
CVE-2025-26210 is a vulnerability with a CVSS score of 8.8 (HIGH). DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended b...
How severe is CVE-2025-26210?
CVE-2025-26210 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26210?
Check the references section above for vendor advisories and patch information. Affected products include: Deepseek Deepseek-R1, Deepseek Deepseek-V2, Deepseek Deepseek-V3.