PT-2025-21945 · Chatgpt · Chatgpt
Zer0Dac
·
Published
2025-05-19
·
Updated
2025-06-12
·
CVE-2025-43714
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ChatGPT system through 2025-03-30
Description:
The issue allows HTML injection within most modern graphical web browsers due to the inline rendering of SVG documents. This is instead of rendering them as text inside a code block.
Recommendations:
For the ChatGPT system through 2025-03-30, consider disabling inline rendering of SVG documents as a temporary workaround until a patch is available. Restrict access to SVG rendering to minimize the risk of HTML injection.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chatgpt