open-webui
v0.1.125npm· JavaScript  .
License
No license declared.
Dependencies
19 direct dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHOpen WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) VulnerabilityGHSA-5ccf-884p-4jjq Published 2025-03-20
- HIGHOpen WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'
- HIGHOpen WebUI Uncontrolled Resource Consumption vulnerabilityGHSA-chf7-q7m5-fq92 Published 2025-03-20
- HIGHOpen WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- HIGHOpen WebUI has Stored XSS in Banner Component via Improper Sanitization Order
- HIGHOpen WebUI Uncontrolled Resource Consumption vulnerabilityGHSA-g3mx-83mp-3rwc Published 2025-03-20
- HIGHopen-webui Vulnerable to Stored XSS via Model Description
- HIGHOpen WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
- HIGHOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
- MEDIUMOpen WebUI Has Stored Cross-Site Scripting in SVG Renderer
Recent releases
- 0.1.1252 years ago