Cross-site scripting in Open WebUI - #VU152712
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to access victim accounts with their full permissions.
The vulnerability exists due to improper neutralization of input during web page generation in the chat markdown link renderer when rendering a markdown link with a javascript: URL that a victim clicks. A remote user can share a chat containing a markdown link with a javascript: URL to access victim accounts with their full permissions.
WebKit browsers execute the URL on a plain click, while Firefox requires a middle click or a Ctrl/Shift click; Chromium-based browsers do not execute it.