Origin validation error in Open WebUI - #VU152710
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain full API access as the victim.
The vulnerability exists due to an origin validation error in the community stats message handler when processing cross-origin verify:chat messages. A remote attacker can send a crafted verify:chat message with a path-traversal chat ID to gain full API access as the victim.
Exploitation requires community sharing to be enabled and a signed-in victim to visit an attacker-controlled page that opens Open WebUI in a popup.