PT-2026-41198 · Unknown · Open-Webui

Published

2026-03-11

·

Updated

2026-05-16

·

CVE-2026-45665

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.8.0
Description A Stored Cross-Site Scripting (XSS) issue exists in the Banner component due to an improper sanitization order where DOMPurify.sanitize() is executed before marked.parse(). This allows a malicious administrator to plant a payload in the global banner that bypasses security mechanisms. Because the banner is rendered for all users, including the Super Admin, this can lead to privilege escalation by stealing the Super Admin's session token. The flaw is located in the src/lib/components/common/Banner.svelte file.
Recommendations Update to version 0.8.0. As a temporary workaround, restrict administrator access to the Banner settings in the interface to minimize the risk of payload injection.

Exploit

Fix

LPE

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-07140
CVE-2026-45665
GHSA-CQP4-QQVG-3787

Affected Products

Open-Webui