Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
- Severity:
- High
Description
The functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when ‘Insert Prompt as Rich Text’ is enabled, since the prompt body is assigned to the DOM sink .innerHtml without sanitisation.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.6.34
- Patched version(s): 0.6.35
References
Related Issues
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes - @tinacms/mdx - CVE-2026-55661
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on November 27, 2025


