Cross-site scripting in Open WebUI - CVE-2026-26193
Published: April 24, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the ResponseMessage.svelte iFrame embed handling when rendering user-controlled response message embeds. A remote user can modify chat history to inject a crafted embeds value to execute arbitrary script in a victim's browser.
User interaction is required to view the affected chat or a shared chat link.