VYPR

npm package

open-webui

pkg:npm/open-webui

Vulnerabilities (5)

  • CVE-2025-65959HigDec 4, 2025
    affected < 0.6.37fixed 0.6.37

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags int

  • CVE-2025-64496HigNov 8, 2025
    affected < 0.6.35fixed 0.6.35

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in v

  • CVE-2025-64495HigNov 8, 2025
    affected < 0.6.35fixed 0.6.35

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 and below, the functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when 'Insert Prompt as Rich Text' is enabled, since the pro

  • CVE-2024-12537Mar 20, 2025
    affected <= 0.3.32

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-12534Mar 20, 2025
    affected <= 0.3.32

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.