PT-2026-20917 · Unknown · Open-Webui
Gg0H
·
Published
2026-02-19
·
Updated
2026-03-18
·
CVE-2026-26192
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions prior to 0.7.0
Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Modifying chat history before version 0.7.0 allows manipulation of the
html property within document metadata. This causes the frontend to interpret document contents as HTML and render them within an iFrame when a citation is previewed, leading to stored cross-site scripting (XSS). The payload executes when the citation is viewed, including in shared chats. The issue involves a code path triggered by document contents treated as HTML.Recommendations
Update to version 0.7.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui