CVE-2026-45346
EUVD-2026-3065115.05.2026, 22:16
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openwebui | open_webui | 𝑥 < 0.6.31 |
𝑥
= Vulnerable software versions