Medium severity6.5NVD Advisory· Published May 19, 2025· Updated Jun 17, 2026
CVE-2025-43714
CVE-2025-43714
Description
The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.
Affected products
3- ChatGPT/ChatGPTdescription
Patches
Vulnerability mechanics
References
1- medium.com/@zer0dac/chatgpt-a-potential-phishing-vector-via-html-injection-bf703c79590anvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.