DeepSeek Community Flags 9 Security Flaws and 7 API Bugs, Offers XMR Bounty
The DeepSeek open-source AI project is facing scrutiny after its community identified nine critical security vulnerabilities and seven API bugs. Among the security issues are an SQL injection flaw reportedly exposing credit card data, a one-click XSS vulnerability capable of stealing user tokens, and a prompt injection jailbreak affecting versions 2.1.0 and 2.1.1. On the API side, developers have reported problems including a high rate of empty responses, JSON decode errors affecting roughly 80% of requests, and the model incorrectly identifying itself as GPT-4. A bug bounty program denominated in Monero (XMR) has been launched to incentivize community-driven security research and fixes. Developers integrating DeepSeek are also being warned against exposing API keys on the client side, particularly in Next.js environments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in