Cross-site scripting in Open WebUI - CVE-2025-65959
Published: April 24, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript code and steal session tokens.
The vulnerability exists due to cross-site scripting in the Notes PDF download functionality in src/lib/components/notes/utils.ts downloadPdf() when processing imported markdown content during PDF generation. A remote user can import or share a specially crafted markdown file containing malicious SVG tags to execute arbitrary JavaScript code and steal session tokens.
User interaction is required when the victim downloads the note as a PDF.