Vulnerabilities/

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF

Severity:
High

Description

A Stored XSS vulnerability has been discovered in Open-WebUI’s Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing them to execute arbitrary JavaScript code and steal session tokens when a victim downloads the note as PDF.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on December 05, 2025