CVE-2025-26210: XSS
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26210?
CVE-2025-26210 is classified with a high severity due to its potential for remote code execution through XSS vulnerabilities.
How do I fix CVE-2025-26210?
To fix CVE-2025-26210, upgrade DeepSeek R1 to version V3.2 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2025-26210?
CVE-2025-26210 is a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute malicious scripts.
Who is affected by CVE-2025-26210?
CVE-2025-26210 affects users running DeepSeek R1 versions up to and including V3.1.
Can CVE-2025-26210 be exploited remotely?
Yes, CVE-2025-26210 can be exploited remotely, which allows attackers to execute arbitrary code on vulnerable systems.