Cross-site scripting in Open WebUI - #VU130935
Published: May 11, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and steal session tokens.
The vulnerability exists due to cross-site scripting in the /api/v1/audio/transcriptions upload endpoint and the /cache/{path} route when processing a user-supplied filename extension and serving the uploaded file as web content. A remote user can upload a specially crafted polyglot file and trick the victim into opening the resulting URL to execute arbitrary script in a victim's browser and steal session tokens.
User interaction is required, and the issue is exploitable by a verified user with the default-on chat.stt permission.