Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v669-8m26-4r4w

Опубликовано: 03 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An Cross-Site Scripting (XSS) vulnerability in DeepSeek R1 through V3.1 allows a remote attacker to execute arbitrary code via unspecified input fields.

An Cross-Site Scripting (XSS) vulnerability in DeepSeek R1 through V3.1 allows a remote attacker to execute arbitrary code via unspecified input fields.

EPSS

Процентиль: 20%
0.00064
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.

EPSS

Процентиль: 20%
0.00064
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79