Open WebUI Extensible Platform Vulnerability in Vega Code Rendering
CVE-2026-70480

4.1MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-70480?

The Open WebUI platform, versions 0.6.34 to 0.11.0, contains a vulnerability due to improper handling of vega and vega-lite fenced code blocks. By exploiting this flaw, an attacker can craft these blocks to send unauthorized outbound GET requests from a user's browser to specified same-origin or CORS-permissive targets. This risk arises when users can insert such code into chat content, allowing for the capture of responses directly into the rendered page. The vulnerability is mitigated in version 0.11.0.

Affected Version(s)

open-webui >= 0.6.34, < 0.11.0

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.