Junglewise Threat Intelligence

CVE-2026-26192: Open WebUI Stored XSS in CitationModal via document metadata

CVE-2026-26192 · Severity: high · CVSS 7.3 · Published 2026-07-07

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a popular interface for interacting with large language models, is vulnerable to a security flaw where malicious users can embed hidden scripts in chat documents. If a user or administrator views a shared chat and clicks on a citation, the attacker's script can run in their browser. This could allow an attacker to steal login tokens or, in the case of administrators, potentially gain deeper access to the server.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Open WebUI's citation modal. By intercepting and modifying the chat history save request, an attacker can set the 'html' property to true within document metadata. This forces the frontend to render the document content within an iFrame. Because the iFrame implementation in 'CitationModal.svelte' includes 'allow-scripts' and 'allow-same-origin' without sufficient sandboxing, arbitrary JavaScript can be executed when a victim previews the citation. This can be triggered in shared chats, leading to session hijacking or potential remote code execution (RCE) chains against administrators. The issue is fixed in version 0.7.0.

Affected products

  • Open WebUI open-webui < 0.7.0

Timeline

  • 2026-02-17: patched: Version 0.7.0 released
  • 2026-02-19: advisory: NVD publication date
  • 2026-07-07: disclosed: GitHub Advisory published

References

Related threats