Vulnerability Description
The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openai | Chatgpt | <= 2025-03-30 |
Related Weaknesses (CWE)
References
- https://medium.com/@zer0dac/chatgpt-a-potential-phishing-vector-via-html-injectiExploitThird Party Advisory
FAQ
What is CVE-2025-43714?
CVE-2025-43714 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern ...
How severe is CVE-2025-43714?
CVE-2025-43714 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-43714?
Check the references section above for vendor advisories and patch information. Affected products include: Openai Chatgpt.