PT-2025-21945 · Chatgpt · Chatgpt

·

CVE-2025-43714

·

Published

2025-05-19

·

Updated

2025-06-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ChatGPT system through 2025-03-30
Description: The issue allows HTML injection within most modern graphical web browsers due to the inline rendering of SVG documents. This is instead of rendering them as text inside a code block.
Recommendations: For the ChatGPT system through 2025-03-30, consider disabling inline rendering of SVG documents as a temporary workaround until a patch is available. Restrict access to SVG rendering to minimize the risk of HTML injection.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-43714

Affected Products

Chatgpt