Deepseek develops a family of large language model and AI inference products where the observed vulnerability signal centers on web-facing application-layer input handling, specifically cross-site scripting weaknesses. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deepseek over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26210HIGH DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated tha | Sep 3, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-63872MEDIUM DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content. | Dec 2, 2025 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deepseek.
Media articles that mention a CVE ID that affects a product developed by Deepseek — matched by CVE ID, not by vendor name.