CVE Database
/

CVE-2024-6706

Back to search

CVE-2024-6706

Published: Aug 7, 2024

Modified: Aug 8, 2024

PUBLISHED

Description

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

VendorProductVersions

Open WebUI

Open WebUI

affected
0.1.105

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now