Cross-site scripting in Open WebUI - #VU140758

 

Cross-site scripting in Open WebUI - #VU140758

Published: August 3, 2026


Vulnerability identifier: #VU140758
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser and take over the viewing account.

The vulnerability exists due to cross-site scripting in the KaTeX render-error fallback in rendered messages when rendering a stored message containing crafted math input that causes KaTeX rendering to fail. A remote user can store a specially crafted message and get a victim to open it to execute arbitrary script in the victim's browser and take over the viewing account.

User interaction is required for the target to view the crafted content, such as through a shared chat, a channel, or another message surface.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.0

External References

Related Security Bulletins