Cross-site scripting in Open WebUI - CVE-2026-44721
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.
The vulnerability exists due to cross-site scripting in model description rendering in the chat UI when processing a crafted model description containing a javascript: link. A remote user can create a malicious model description to execute arbitrary JavaScript in the browser of another user.
User interaction is required, and the victim must view the malicious model and click the rendered hyperlink.