Open WebUI Extensible Platform Vulnerability in Vega Code Rendering
CVE-2026-70480
4.1MEDIUM
What is CVE-2026-70480?
The Open WebUI platform, versions 0.6.34 to 0.11.0, contains a vulnerability due to improper handling of vega and vega-lite fenced code blocks. By exploiting this flaw, an attacker can craft these blocks to send unauthorized outbound GET requests from a user's browser to specified same-origin or CORS-permissive targets. This risk arises when users can insert such code into chat content, allowing for the capture of responses directly into the rendered page. The vulnerability is mitigated in version 0.11.0.
Affected Version(s)
open-webui >= 0.6.34, < 0.11.0
