CVE 5.1 MEDIUM

Open WebUI: Stored Cross-Site Scripting in SVG Renderer_CVE-2026-45346

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31.

Basic Information

ID CVE-2026-45346
Source GitHub_M
Published May 15, 2026 at 21:15

Affected Product

Vendor open-webui
Product open-webui
Version < 0.6.31
Affected Versions open-webui open-webui < 0.6.31

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.