Cross-site scripting in Open WebUI - #VU140758
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser and take over the viewing account.
The vulnerability exists due to cross-site scripting in the KaTeX render-error fallback in rendered messages when rendering a stored message containing crafted math input that causes KaTeX rendering to fail. A remote user can store a specially crafted message and get a victim to open it to execute arbitrary script in the victim's browser and take over the viewing account.
User interaction is required for the target to view the crafted content, such as through a shared chat, a channel, or another message surface.