Cross-site scripting in Open WebUI - #VU140756
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute script in the application origin and take over a victim account.
The vulnerability exists due to cross-site scripting in the terminal file preview iframe in FilePreview.svelte when rendering HTML files served through the terminal file preview path. A remote user can cause a crafted HTML file to be previewed to execute script in the application origin and take over a victim account.
Exploitation requires a configured and reachable terminal server, and no victim interaction beyond having the chat open because the preview opens automatically. Instances without a terminal server configured are not affected.