PT-2026-41164 · Unknown · Open-Webui

Published

2026-05-14

·

Updated

2026-05-16

·

CVE-2026-45303

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.6.5
Description Scripts can be injected and executed through the HTML rendering view. The frontend includes a function to visualize HTML content of a chat by embedding it in an iFrame. However, the use of the sandbox directive with allow-scripts, allow-forms, and allow-same-origin permissions allows the content to execute scripts and access parent data, such as local storage, effectively nullifying the sandbox protections. This can lead to a Self-XSS attack or be leveraged against other users if an attacker tricks a user into entering specific input, uses the Chat Share function to clone a chat, embeds instructions in uploaded files, or imports conversations via settings.
Recommendations Update to version 0.6.5.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-45303
GHSA-4VRC-M9CH-6M3R

Affected Products

Open-Webui