CVE-2026-45346
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, ther
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31.
MEDIUM · CVSS 5.4
EPSS 0.0003
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0