Description
A Stored XSS vulnerability has been discovered in Open-WebUI’s Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing them to execute arbitrary JavaScript code and steal session tokens when a victim downloads the note as PDF.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.36
- Patched version(s): 0.6.37
References
Related Issues
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- wetty vulnerable to DOM XSS via file-download filename - CVE-2026-49864
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on December 05, 2025


