Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Open WebUI - CVE-2026-45346

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Open WebUI - CVE-2026-45346

Published: May 11, 2026


Vulnerability identifier: #VU130941
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45346
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser.

The vulnerability exists due to improper neutralization of script-related html tags in the SVG renderer when rendering edited SVG content. A remote user can save crafted HTML or JavaScript in a thread and share it with another user to execute arbitrary script in the victim's browser.

User interaction is required when another user opens the shared thread containing the rendered SVG.


Affected software

Open WebUI

How to mitigate CVE-2026-45346

Install security update from vendor's website.

Open WebUI - update to 0.6.31

External References

Related Security Bulletins