Cross-site scripting in Open WebUI - #VU130240

 

Cross-site scripting in Open WebUI - #VU130240

Published: May 6, 2026


Vulnerability identifier: #VU130240
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Open WebUI
Affected software:
Open WebUI

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary script in a victim's browser.

The vulnerability exists due to cross-site scripting in the excel file preview component when rendering a crafted XLSX attachment for preview. A remote user can upload and share a specially crafted XLSX file to execute arbitrary script in a victim's browser.

User interaction is required to open the file modal and select the preview tab, and the issue can be triggered through shared chats.


Remediation

Install security update from vendor's website.

Sources