top of page
perceptive_background_267k.jpg

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexR…

Published:

4 augustus 2026 om 00:00:00

Alert date:

5 augustus 2026 om 00:03:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A stored Cross-Site Scripting (XSS) vulnerability exists in Open WebUI versions 0.10.0 through 0.11.0, affecting the KatexRenderer.svelte component. When a crafted math block causes KaTeX to fail with a stack overflow rather than a parse error, the error catch branch inserts the raw math source as unescaped HTML using Svelte's {@html} directive. This allows arbitrary JavaScript execution in the browser of any user who views the malicious chat message, including shared chats and channels. Attackers can steal session tokens stored in localStorage, enabling account takeover. Administrator accounts are particularly at risk, as compromise could lead to full platform takeover. The vulnerability is fixed in Open WebUI version 0.11.0. A GitHub security advisory and corresponding pull request detail the remediation.

Technical details

Mitigation steps:

Affected products:

Open WebUI 0.10.0
Open WebUI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page