Chatgpt · Chatgpt · CVE-2025-43714
Name of the Vulnerable Software and Affected Versions:
ChatGPT system through 2025-03-30
Description:
The issue allows HTML injection within most modern graphical web browsers due to the inline rendering of SVG documents. This is instead of rendering them as text inside a code block.
Recommendations:
For the ChatGPT system through 2025-03-30, consider disabling inline rendering of SVG documents as a temporary workaround until a patch is available. Restrict access to SVG rendering to minimize the risk of HTML injection.