High severity8.8NVD Advisory· Published Sep 3, 2025· Updated Jun 17, 2026
CVE-2025-26210
CVE-2025-26210
Description
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:deepseek:deepseek-r1:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:deepseek:deepseek-v2:-:*:*:*:*:*:*:*
- cpe:2.3:a:deepseek:deepseek-v3:1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- hackmd.io/@MrqrFIlhQFi7vUwkqbrXDw/deepseeknvdExploitThird Party Advisory
- youtu.be/IgQwy52FVT4nvdExploit
- deepseek.comnvdPermissions Required
News mentions
0No linked articles in our index yet.