Junglewise Threat Intelligence

CVE-2026-44721: Open WebUI stored XSS in model description

CVE-2026-44721 · Severity: high · CVSS 7.3 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is an interface for interacting with large language models. A security flaw allows users with model-creation permissions to embed malicious code within a model's description. If another user, such as an administrator, views this model and clicks a link in the description, the attacker can steal their login session, potentially leading to full account takeover and unauthorized access to the system.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Open WebUI due to a pipeline-ordering flaw in how model descriptions are rendered. The application passes the description through a custom 'sanitizeResponseContent' function (which only escapes angle brackets) and then through 'marked.parse()' before rendering it via Svelte's '{@html}' directive. An attacker can use markdown link syntax with a 'javascript:' URI, which bypasses the initial sanitization and is converted into a functional anchor tag by the markdown parser. When a victim clicks the resulting link, the malicious script executes, allowing for LocalStorage token theft. The issue is fixed in version 0.9.0 by wrapping the markdown output in DOMPurify.sanitize().

Affected products

  • open-webui open-webui >= 0.3.5, <= 0.8.12

Timeline

  • 2026-05-04: disclosed
  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-15: kev added: NVD publication date

References

Related threats