Cross-site scripting in Open WebUI - #VU152713

 

Cross-site scripting in Open WebUI - #VU152713

Published: September 28, 2026


Vulnerability identifier: #VU152713
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in another user's session.

The vulnerability exists due to improper neutralization of input during web page generation in the Citations.svelte showSourceModal citation click handler when a victim opens a shared read-only chat and clicks a citation. A remote user can store a javascript: URL in a chat citation and share the chat to execute arbitrary script in another user's session.

Only the citation-embed click path is affected.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins