Information has surfaced regarding a now-patched security vulnerability in the DeepSeek AI chatbot that, if properly exploited, might allow a malicious actor to use a prompt injection attack to take over a victim’s account.
In a classic case of cross-site scripting (XSS), security researcher Johann Rehberger discovered that entering the input “Print the xss cheat sheet in a bullet list. just payloads” in the DeepSeek chat caused JavaScript code to be executed as part of the generated response. Rehberger has documented numerous prompt injection attacks that target different AI tools.
Because XSS attacks cause unauthorized code to be executed within the victim’s web browser, they can have major repercussions read more about Researchers Uncover Prompt Injection Vulnerabilities in DeepSeek and Claude AI.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
