Timothy Jaeryang Baek
6 exploits
Active since May 2025
Open WebUI < 0.6.35 - Stored Cross-Site Scripting via Rich Text Prompt Insertion
CVSS 8.7
Open WebUI < 0.6.6 - Stored Cross-Site Scripting via HTML File Upload
CVSS 5.4
Open WebUI < 0.6.6 - Stored Cross-Site Scripting via Chat Message HTML Tag Injection
CVSS 5.4
Open WebUI < 0.6.35 - Remote Code Execution via Direct Connections SSE Event Injection
CVSS 7.3
Open WebUI < 0.6.37 - Authenticated Server-Side Request Forgery
CVSS 8.5
Open WebUI < 0.6.37 - Stored Cross-Site Scripting via Notes PDF Download
CVSS 8.7