Cross-site scripting in Open WebUI - #VU152712

 

Cross-site scripting in Open WebUI - #VU152712

Published: September 28, 2026


Vulnerability identifier: #VU152712
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access victim accounts with their full permissions.

The vulnerability exists due to improper neutralization of input during web page generation in the chat markdown link renderer when rendering a markdown link with a javascript: URL that a victim clicks. A remote user can share a chat containing a markdown link with a javascript: URL to access victim accounts with their full permissions.

WebKit browsers execute the URL on a plain click, while Firefox requires a middle click or a Ctrl/Shift click; Chromium-based browsers do not execute it.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins