Cross-site scripting in Open WebUI - CVE-2026-59214

 

Cross-site scripting in Open WebUI - CVE-2026-59214

Published: June 30, 2026


Vulnerability identifier: #VU135953
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-59214
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the server.

The vulnerability exists due to cross-site scripting in the Pyodide code execution feature when processing Python code stored in a shared chat and executed in a same-origin worker. A remote user can store a crafted payload in a shared chat and induce the victim to click Run to execute arbitrary code on the server.

User interaction is required, and exploitation for server-side code execution depends on the victim having admin privileges or the workspace.functions or workspace.tools permissions. Open WebUI must be configured to use Pyodide.


Affected software

Open WebUI

How to mitigate CVE-2026-59214

Install security update from vendor's website.

Open WebUI - update to 0.10.0

External References

Related Security Bulletins