Junglewise Threat Intelligence

CVE-2026-44549: Open WebUI stored XSS in Excel file preview

CVE-2026-44549 · Severity: high · CVSS 7.3 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a user interface for interacting with large language models, is vulnerable to a security flaw in how it handles Excel file previews. An attacker can upload a specially crafted Excel file that, when viewed by another user or an administrator, executes malicious code in their browser. This could allow an attacker to steal user session tokens or, in the case of administrators, potentially gain further control over the server.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Open WebUI versions 0.7.2 and prior. The vulnerability is rooted in the `FileItemModal.svelte` component, which uses the SheetJS `sheet_to_html` function to generate a preview of uploaded XLSX files. The resulting HTML is injected into the DOM using Svelte's `@html` tag without prior sanitization. An attacker with low privileges can upload a weaponized Excel file containing an XSS payload; when a victim (including administrators) previews the file in a shared chat, the payload executes in their browser context. This can be used to exfiltrate session tokens from local storage or facilitate a multi-stage attack leading to RCE. The issue is addressed in version 0.8.0 by implementing proper HTML sanitization.

Affected products

  • Open WebUI open-webui <= 0.7.2

Timeline

  • 2026-05-05: disclosed
  • 2026-05-08: advisory
  • 2026-05-08: patched: Fixed in version 0.8.0

References

Related threats