Executive brief
Open WebUI is an interface for interacting with large language models. A security flaw allows users with model-creation permissions to embed malicious code within a model's description. If another user, such as an administrator, views this model and clicks a link in the description, the attacker can steal their login session, potentially leading to full account takeover and unauthorized access to the system.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Open WebUI due to a pipeline-ordering flaw in how model descriptions are rendered. The application passes the description through a custom 'sanitizeResponseContent' function (which only escapes angle brackets) and then through 'marked.parse()' before rendering it via Svelte's '{@html}' directive. An attacker can use markdown link syntax with a 'javascript:' URI, which bypasses the initial sanitization and is converted into a functional anchor tag by the markdown parser. When a victim clicks the resulting link, the malicious script executes, allowing for LocalStorage token theft. The issue is fixed in version 0.9.0 by wrapping the markdown output in DOMPurify.sanitize().
Affected products
- open-webui open-webui >= 0.3.5, <= 0.8.12
Timeline
- 2026-05-04: disclosed
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-15: kev added: NVD publication date