Cross-site scripting in Open WebUI - CVE-2026-44721

 

Cross-site scripting in Open WebUI - CVE-2026-44721

Published: May 5, 2026


Vulnerability identifier: #VU129658
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-44721
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.

The vulnerability exists due to cross-site scripting in model description rendering in the chat UI when processing a crafted model description containing a javascript: link. A remote user can create a malicious model description to execute arbitrary JavaScript in the browser of another user.

User interaction is required, and the victim must view the malicious model and click the rendered hyperlink.


Affected software

Open WebUI

How to mitigate CVE-2026-44721

Install security update from vendor's website.

Open WebUI - update to 0.9.0

External References

Related Security Bulletins