Vulnerabilities/

Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order

Severity:
High

Description

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library).

This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the global banner.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on May 19, 2026