VDB
KO
MEDIUM 6.1

PYSEC-2026-1722

Open WebUI Stored Cross-Site Scripting Vulnerability

Quick fix

PYSEC-2026-1722 — open-webui: upgrade to the fixed version with the command below.

pip install --upgrade 'open-webui>=0.3.14'

Details

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / open-webui
Introduced in: 0 Fixed in: 0.3.14
Fix pip install --upgrade 'open-webui>=0.3.14'

References