Cross-site scripting in Open WebUI - CVE-2026-45303
Published: May 11, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and disclose sensitive information.
The vulnerability exists due to cross-site scripting in the HTML rendering view when rendering chat content as HTML in a sandboxed iframe with script execution and same-origin access enabled. A remote user can inject a crafted script into chat content to execute arbitrary script in a victim's browser and disclose sensitive information.
User interaction is required, and exploitation against another user's context depends on vectors such as shared or imported conversations or uploaded content being rendered.