Cross-site scripting in Open WebUI - #VU129658
Published: May 5, 2026
Open WebUI
Open WebUI
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.
The vulnerability exists due to cross-site scripting in model description rendering in the chat UI when processing a crafted model description containing a javascript: link. A remote user can create a malicious model description to execute arbitrary JavaScript in the browser of another user.
User interaction is required, and the victim must view the malicious model and click the rendered hyperlink.