Medium severity6.1NVD Advisory· Published Aug 7, 2024· Updated Jun 17, 2026
CVE-2024-6706
CVE-2024-6706
Description
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-webuiPyPI | <= 0.1.105 | — |
Affected products
3- cpe:2.3:a:openwebui:open_webui:0.1.105:*:*:*:*:*:*:*
- Open WebUI/Open WebUIv5Range: 0.1.105
Patches
Vulnerability mechanics
References
5- korelogic.com/Resources/Advisories/KL-001-2024-005.txtnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5jp3-wp5v-5363ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-6706ghsaADVISORY
- seclists.org/fulldisclosure/2024/Aug/3nvd
- www.openwall.com/lists/oss-security/2024/08/08/6nvd
News mentions
0No linked articles in our index yet.