CVE-2025-43714: Command Injection
The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43714?
CVE-2025-43714 is classified as a high severity vulnerability due to its potential for HTML injection in web browsers.
How do I fix CVE-2025-43714?
To fix CVE-2025-43714, update to a version of OpenAI ChatGPT released after 2025-03-30 that addresses the inline SVG rendering issue.
Which versions of OpenAI ChatGPT are affected by CVE-2025-43714?
CVE-2025-43714 affects all versions of OpenAI ChatGPT up to and including 2025-03-30.
What type of attack can CVE-2025-43714 facilitate?
CVE-2025-43714 can facilitate HTML injection attacks, which may lead to phishing or other malicious web activities.
Is user data at risk due to CVE-2025-43714?
Yes, user data may be at risk due to the potential for attackers to exploit HTML injection via CVE-2025-43714.