openwebui

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Security
SecurityMEDIUM
references/plugin-development-events.md

No explicit malicious code is shown; this is an interface/specification description. However, it documents a critical, non-sandboxed browser execution primitive (`execute` → `new Function(code)` with DOM/cookie/localStorage access) and shows how event payloads can be introduced via external tool forwarding. If `execute.code` or event dispatch is influenced by untrusted parties or lacks strict allowlisting/authorization, the system can enable direct browser compromise (session theft/exfiltration/DOM manipulation). Persistence of some event types and continued task execution after disconnect can further amplify impact. Overall: high design-level security risk; malware presence cannot be proven from this fragment alone.

Confidence: 62%Severity: 88%
Audit Metadata
Analyzed At
Aug 22, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/kettleofketchup%2Fkettleofskills%2Fopenwebui%2F@ec933497108eba321953c9069c546ade8788f629399a9ea9b4be6b61a5640f24
Security Audit — socket — openwebui