CVE-2025-26210: Deepseek Deepseek-r1
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.
Affected products
- Deepseek Deepseek-r1: version 1.0 only
- Deepseek Deepseek-v2: affected versions not specified
- Deepseek Deepseek-v3: version 1.0 only
Published 2025-09-03. Last modified 2026-06-17.