Cross-site scripting in Open WebUI - #VU130240
Published: May 6, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the excel file preview component when rendering a crafted XLSX attachment for preview. A remote user can upload and share a specially crafted XLSX file to execute arbitrary script in a victim's browser.
User interaction is required to open the file modal and select the preview tab, and the issue can be triggered through shared chats.