Description
There is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.31
- Patched version(s): 0.6.31
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI Has Stored Cross-Site Scripting in SVG Renderer and gives you actionable findings to investigate.
Start a free scanRelated Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- DbGate has cross site scripting via the SVG Icon String Handler component - CVE-2026-6216
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
You might also like:
See something that needs correcting? Let us knowUpdated May 19, 2026


