CVE-2025-63872: XSS
DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63872?
CVE-2025-63872 is classified as a high severity vulnerability due to its potential for arbitrary JavaScript execution.
How do I fix CVE-2025-63872?
To mitigate CVE-2025-63872, ensure proper sanitization of user-generated SVG content and implement Content Security Policy headers.
What impact does CVE-2025-63872 have on users?
Users affected by CVE-2025-63872 may be susceptible to data theft or unauthorized actions if an attacker exploits the XSS vulnerability.
Which versions of DeepSeek are affected by CVE-2025-63872?
CVE-2025-63872 specifically impacts DeepSeek version 3.2 and potentially earlier versions if they handle SVG content similarly.
How can I determine if my system is vulnerable to CVE-2025-63872?
You can determine vulnerability by checking if your system uses DeepSeek version 3.2 and reviewing how it processes SVG content.