Vulnerabilities/

Open WebUI Has Stored Cross-Site Scripting in SVG Renderer

Severity:
Medium

Description

There is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on May 19, 2026