open-webui
   Vulnerabilityhigh
GHSA-5ccf-884p-4jjq
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'high
GHSA-8wvc-869r-xfqf · fixed in 0.6.37
- Open WebUI Uncontrolled Resource Consumption vulnerabilityhigh
GHSA-chf7-q7m5-fq92
- Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Eventshigh
GHSA-cm35-v4vp-5xvx · fixed in 0.6.35
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Orderhigh
GHSA-cqp4-qqvg-3787 · fixed in 0.8.0
- Open WebUI Uncontrolled Resource Consumption vulnerabilityhigh
GHSA-g3mx-83mp-3rwc
- open-webui Vulnerable to Stored XSS via Model Descriptionhigh
GHSA-gf5m-wcrh-7928 · fixed in 0.9.0
- Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Executionhigh
GHSA-p4fx-23fq-jfg6 · fixed in 0.9.5
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderermoderate
GHSA-r29h-37fj-x2w6 · fixed in 0.6.31
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEhigh
GHSA-w7xj-8fx7-wfch · fixed in 0.6.35
Downloads — last 30 days
226 total▼ 26.2% vs prior week
Jul 11Aug 9