Description
There is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.6.31
- Patched version(s): 0.6.31
References
Related Issues
- NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability - CVE-2026-30048
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- DbGate has cross site scripting via the SVG Icon String Handler component - CVE-2026-6216
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on May 19, 2026


