THREAT OPS › Threat News › [GHSA] GHSA-pwxh-7358-jq2x (high) — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
[GHSA] GHSA-pwxh-7358-jq2x (high) — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
GHSA-pwxh-7358-jq2x Severity: high CVE: CVE-2026-70492
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
## Summary Any authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as
Indicators of compromise
- CVE-2026-70492cve
Original source: https://github.com/advisories/GHSA-pwxh-7358-jq2x