Vulnerabilities/

open-webui Vulnerable to Stored XSS via Model Description

Severity:
High

Description

[!IMPORTANT] Relationship to CVE-2024-7990

CVE-2024-7990 (issued by huntr.dev, March 2025) describes a stored XSS in the same field — the model description — but exploits a different bypass mechanism: a second-order injection through the sanitizeResponseContent function’s video-tag placeholder restoration logic in v0.3.x.

Recommendation

Update the open-webui package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
open-webui
Anything's wrong? Let us know Last updated on May 15, 2026