pkg:npm/open-webui
9 total CVEsHIGH8
✅ Check your installed version
All known vulnerabilities
- from 0, < 0.6.37
- HIGH8.7CVE-2025-64495Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEfrom 0, < 0.6.35
- from 0, < 0.8.0
- from 0, <= 0.3.32
- from 0, <= 0.3.32
- from 0, < 0.9.0
- HIGH7.3CVE-2025-64496Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Eventsfrom 0, < 0.6.35
- HIGH7.2CVE-2026-45395Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Executionfrom 0, < 0.9.5
- from 0, < 0.6.31