Cross-site scripting in Open WebUI - #VU152709

 

Cross-site scripting in Open WebUI - #VU152709

Published: September 28, 2026


Vulnerability identifier: #VU152709
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to steal session tokens and gain administrative control of the instance.

The vulnerability exists due to improper neutralization of input during web page generation in the DOCX preview component when rendering a crafted DOCX attachment in Preview view. A remote user can upload a crafted DOCX document containing active content to execute script in the viewer's authenticated browser session and steal the viewer's session token.

User interaction is required to open a shared chat, open the attachment, and switch to Preview view.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins