THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pwxh-7358-jq2x (high) — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

[GHSA] GHSA-pwxh-7358-jq2x (high) — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

medgithub_advisoriesPublished 2026-08-04

GHSA-pwxh-7358-jq2x Severity: high CVE: CVE-2026-70492

Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

## Summary Any authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pwxh-7358-jq2x