CVE-2026-70492General(openwebui / open_webui)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch openwebui open_webui systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} rather than as text, so script in the message runs in the browser of whoever views it, including shared chats and channels. The viewer's session token in localStorage can be stolen, and an administrator viewer can have their account taken over. This issue is fixed in 0.11.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-05: 3Patch / Workaround · 2026-08-05: 1Technical Details · 2026-08-05: 208-05
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-70492 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRendere… https://www.cve.org/CVERecord?id=CVE-2026-70492

    Post summary

    The post merely references CVE‑2026‑70492 in Open WebUI, noting impacted versions and a source file path, but lacks details on exploitation, fixes, or PoC.

    100101.4K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-70492 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRendere… https://www.cve.org/CVERecord?id=CVE-2026-70492 ----- Traducción: CVE-2026-70492 Ope… http://infoflow.cloud`

    Post summary

    The post merely references CVE‑2026‑70492 and provides a link to its CVE record, without any information about exploitation, patches, or technical details.

    00010123
    97 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Open WebUI Stored XSS via KaTeX Error Fallback (CVE-2026-70492) Open WebUI’s KaTeX math renderer can stack overflow on crafted chat messages; on render failure it inserts the original math source back into the DOM as raw HTML. This enables stored XSS in shared chats/channels, letting attackers run JS to steal localStorage session tokens and potentially take over accounts. 👉Affected: open-webui < 0.11.0 | Upgrade to 0.11.0

    Post summary

    High‑severity stored XSS in Open WebUI caused by KaTeX error fallback; description of exploit vector and recommendation to upgrade to version 0.11.0

    00000128
    282 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more