Unrated severityNVD Advisory· Published Sep 3, 2025· Updated Sep 8, 2025
CVE-2025-26210
CVE-2025-26210
Description
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
Affected products
2- DeepSeek/DeepSeek R1description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.