VYPR
Vendor

DeepSeek

Products
6
CVEs
3
Across products
6
Status
Private

Products

6

Recent CVEs

3
  • CVE-2025-26210HigSep 3, 2025
    risk 0.57cvss 8.8epss 0.01

    DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.

  • CVE-2026-55604HigJul 9, 2026
    risk 0.49cvss 8.6epss 0.00

    DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` values without binding them to any authenticated principal or transport session. An attacker can…

  • CVE-2025-63872MedDec 2, 2025
    risk 0.40cvss 6.1epss 0.00

    DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content.