DOM XSS Vulnerability in Open WebUI Self-Hosted AI Platform
CVE-2025-64495
8.7HIGH
What is CVE-2025-64495?
Open WebUI, a self-hosted artificial intelligence platform, is exposed to a DOM-based Cross-Site Scripting (XSS) vulnerability in versions up to 0.6.34. This issue arises when the 'Insert Prompt as Rich Text' feature is enabled, leading to unsanitized input being directly inserted into the DOM via the .innerHTML property. If an authorized user creates a custom prompt with a malicious payload, it could potentially compromise other users who utilize that prompt. The issue has since been resolved in version 0.6.35, and users are strongly advised to upgrade to this version to mitigate the risk.
Affected Version(s)
open-webui < 0.6.35
