Cross-site scripting in Open WebUI - CVE-2026-87995
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to take over victim accounts.
The vulnerability exists due to cross-site scripting in the terminal port-preview iframe in src/lib/components/chat/FileNav/PortPreview.svelte when rendering content from a previewed terminal port. A remote user can serve a crafted page on a shared terminal server to take over victim accounts.
User interaction is required for the victim to open the attacker's port preview. Exploitation requires an administrator-configured terminal server reachable by both parties.