Description
[!IMPORTANT] Relationship to CVE-2024-7990
CVE-2024-7990 (issued by huntr.dev, March 2025) describes a stored XSS in the same field — the model description — but exploits a different bypass mechanism: a second-order injection through the sanitizeResponseContent function’s video-tag placeholder restoration logic in v0.3.x.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.8.12
- Patched version(s): 0.9.0
References
Related Issues
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order - CVE-2026-45665
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on May 15, 2026


