VDB
Sign up
MEDIUM6.1

PYSEC-2026-1722

Open WebUI Stored Cross-Site Scripting Vulnerability

Quick fix

PYSEC-2026-1722 — open-webui: upgrade to the fixed version with the command below.

pip install --upgrade 'open-webui>=0.3.14'

Details

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/open-webui
Introduced in: 0Fixed in: 0.3.14
Fixpip install --upgrade 'open-webui>=0.3.14'

References