logo

Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History

ID: 320eacd5-3da0-509a-a513-87c4de3071c7

STIX ID: report--320eacd5-3da0-509a-a513-87c4de3071c7

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2025-01-29

Date Updated: 2026-05-01

...
...

Wiz Research discovered an unauthenticated, publicly accessible ClickHouse instance for DeepSeek (hosts on ports 8123 and 9000) containing over one million log entries with plaintext chat history, API secrets, backend and operational metadata; the exposure allowed arbitrary SQL execution and potential full database control and privilege escalation. Wiz responsibly disclosed the issue to DeepSeek, which remediated the exposure, and the report warns of broader AI industry risks from rapid adoption without adequate infrastructure security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.