Open WebUI disclosed and fixed CVE-2026-70492, a high-severity stored cross-site scripting flaw affecting versions 0.10.0 through before 0.11.0. The bug was traced to src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte, where KaTeX rendering failures could cause the application to insert the original math source into the page through an unescaped {@html} path instead of safely rendering it as text. The vulnerability is rated CVSS 8.7 and classified as CWE-79.
An attacker able to submit a crafted chat message could trigger script execution in the browser of anyone viewing the message, including users in shared chats and channels, creating a path to steal session tokens from localStorage and potentially take over administrator accounts. The issue was reachable through normal message rendering, including malformed or deeply nested brace input that caused non-ParseError KaTeX failures such as RangeError. Open WebUI addressed the flaw by escaping the fallback content rather than injecting it as HTML, and the fix was merged under pull request #26718 before release in version 0.11.0.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-70492 was published, describing a high-severity stored XSS vulnerability in Open WebUI with a CVSS v3.1 score of 8.7. The advisory linked the issue to GitHub Security Advisory GHSA-pwxh-7358-jq2x and recommended updating to version 0.11.0 or later.
The stored XSS vulnerability affecting Open WebUI versions 0.10.0 through before 0.11.0 was fixed in version 0.11.0. The issue could allow crafted chat messages to execute script in other users' browsers and potentially enable administrator account takeover.
Open WebUI merged pull request #26718 into the dev branch, fixing a stored cross-site scripting flaw in the KaTeX render-error fallback by escaping raw math source instead of injecting it as HTML. The merge was recorded as commit bc600d3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.