CVE-2025-65959 | open-webui Open WebUI up to 0.6.36 Markdown File cross site scripting (GHSA-8wvc-869r-xfqf)
A vulnerability labeled as problematic has been found in open-webui Open WebUI up to 0.6.36. Impacted is an unknown function of the component Markdown File Handler. Executing manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-65959. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.