CVE-2026-70492
Open WebUI before 0.11.0: 17-CVE batch - stored XSS in the Katex/markdown renderer, OAuth token-exchange account takeover, SSRF in the web loader and vega renderer, cross-tenant reads of tools/knowledge/chats, and an unsandboxed terminal iframe
- Severity
- high
- Affected product
- Open WebUI
- Affected versions
- Open WebUI < 0.11.0
- Fixed in
- Open WebUI 0.11.0
- Added to NewScan
- 2026-08-05
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Open WebUI from its response and reports this CVE when the detected version falls inside the affected range below.
ONE row for the whole 2026-08-05 Open WebUI batch, following the Bouncy Castle precedent above: every id here is fixed by the same 0.11.0 release, so seventeen rows would be seventeen findings whose single action is 'upgrade to 0.11.0' - noise, not coverage. `cve` carries the highest-scored member (CVE-2026-70492, 8.7) and `cves` publishes the rest to /cve. Range is `lt 0.11.0` with no `ge`: the earliest affected build in the batch is 0.5.0 and several ids read 'until 0.11.0' with no lower bound, so a `ge` could only under-report. Version source is REAL and reachable today: /api/config serves {"name":"Open WebUI","version":"x.y.z"} anonymously, that path is already in the Assetnote apiroutes wordlist so discover_content fetches it, and the tech_signatures row added the same day captures the version from it - verified end to end on 2026-08-05 against ghcr.io/open-webui/open-webui:0.6.5 (0.6.5 -> vulnerable, and the same join reports not-vulnerable once the reported version is >= 0.11.0).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →