10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether open-webui is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.3
CVE-2026-44721
open-webui Vulnerable to Stored XSS via Model Description
HIGH 7.5
CVE-2024-12534
Open WebUI Uncontrolled Resource Consumption vulnerability
HIGH 7.3
CVE-2025-64496
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
HIGH 7.5
CVE-2024-12537
Open WebUI Uncontrolled Resource Consumption vulnerability
HIGH 8.7
CVE-2025-64495
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
HIGH 8.1
CVE-2026-45665
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
UNKNOWN
CVE-2026-45346
Open WebUI Has Stored Cross-Site Scripting in SVG Renderer
HIGH 7.2
CVE-2026-45395
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
HIGH 8.7
CVE-2025-65959
Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'
HIGH 7.5
GHSA-5ccf-884p-4jjq
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes