OsVault/npm/open-webui
npm

open-webui

6 known vulnerabilities · 0 critical · 2 high

CVE-2025-65959

Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'

Published Dec 4, 2025
CVE-2024-12537HIGH

Open WebUI Uncontrolled Resource Consumption vulnerability

Published Mar 20, 2025
CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Published Nov 7, 2025
CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Published Nov 7, 2025
CVE-2024-12534HIGH

Open WebUI Uncontrolled Resource Consumption vulnerability

Published Mar 20, 2025
GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

Published Mar 20, 2025
Check your entire dependency tree at onceRun dependency scan →