Junglewise Threat Intelligence

CVE-2026-44568: Open WebUI stored XSS in AccountPending component

CVE-2026-44568 · Severity: medium · CVSS 4.8 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, an interface for interacting with large language models, is vulnerable to a security flaw where an administrator can inject malicious scripts into the 'Pending User' screen. When a new user waiting for account approval views this screen, the script could execute in their browser, potentially allowing the administrator to steal session tokens or redirect the user to a phishing site. This risk is particularly relevant in environments with multiple administrators where one account might be compromised.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the `AccountPending.svelte` component of Open WebUI. The root cause is an incorrect application order of security filters: the application applies `DOMPurify.sanitize()` to raw Markdown input before it is processed by `marked.parse()`. Because the sanitization occurs before the Markdown is converted to HTML, an attacker can use Markdown link syntax (e.g., `[text](javascript:alert(1))`) to bypass the filter. When the Markdown parser subsequently generates the HTML `<a>` tag, the malicious `javascript:` URI remains unsanitized and is rendered directly via the `{@html}` tag. This allows an authenticated administrator to execute arbitrary JavaScript in the context of any user with a 'pending' role. The issue is patched in version 0.9.0 by reordering the calls to ensure sanitization occurs after HTML generation.

Affected products

  • Open WebUI open-webui <= 0.8.12

Timeline

  • 2026-05-05: disclosed: Initial disclosure by reporter
  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-15: other: NVD record updated

References

Related threats