Cross-site scripting in Open WebUI - CVE-2026-44549

 

Cross-site scripting in Open WebUI - CVE-2026-44549

Published: May 6, 2026


Vulnerability identifier: #VU130240
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-44549
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in a victim's browser.

The vulnerability exists due to cross-site scripting in the excel file preview component when rendering a crafted XLSX attachment for preview. A remote user can upload and share a specially crafted XLSX file to execute arbitrary script in a victim's browser.

User interaction is required to open the file modal and select the preview tab, and the issue can be triggered through shared chats.


Affected software

Open WebUI

How to mitigate CVE-2026-44549

Install security update from vendor's website.

Open WebUI - update to 0.8.0

External References

Related Security Bulletins