Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 14 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:deepseek:deepseek:3.2:*:*:*:*:*:*:* |
Thu, 04 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Deepseek
Deepseek deepseek Deepseek deepseek-v3 |
|
| Vendors & Products |
Deepseek
Deepseek deepseek Deepseek deepseek-v3 |
Tue, 02 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated SVG content. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-02T19:29:45.564Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63872
Updated: 2025-12-02T19:29:39.759Z
Status : Analyzed
Published: 2025-12-02T16:15:55.843
Modified: 2026-01-14T19:21:57.260
Link: CVE-2025-63872
No data.
OpenCVE Enrichment
Updated: 2025-12-04T16:49:01Z