What is CVE-2026-70480?
In Open WebUI, vega and vega-lite fenced code blocks in chat content are rendered by building a Vega view in the viewer browser without a restricted resource loader, posing a security risk. This affects versions from 0.6.34 until 0.11.0. Users are advised to update to the latest version or temporarily disable the affected rendering functionality.
Azərbaycanca: Open WebUI platformunda istifadəçilər tərəfindən yerləşdirilən vega/vega-lite kod blokları məhdud resurs yükləyicisi olmadan brauzerdə işləndiyi üçün potensial təhlükəsizlik riski yaradır. Bu, 0.6.34-dən 0.11.0-a qədər versiyalara təsir edir. İstifadəçilərə dərhal ən son versiyaya yeniləmə və ya müvəqqəti olaraq sözügedən render funksiyasını söndürmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Open WebUI
FAQ2
Which versions of Open WebUI are affected by CVE-2026-70480?
This vulnerability affects Open WebUI versions from 0.6.34 until 0.11.0.
What measures are recommended to mitigate CVE-2026-70480?
Users are advised to immediately update to the latest version or temporarily disable the vega/vega-lite rendering functionality.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.