Junglewise Threat Intelligence

CVE-2026-45303: Open WebUI stored XSS in HTML rendering view

CVE-2026-45303 · Severity: high · CVSS 7.7 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a user interface for interacting with large language models, is vulnerable to a security flaw where malicious code can be embedded in chat conversations. If a user views a specially crafted chat or imports a malicious conversation file, an attacker could steal their login tokens or perform actions on their behalf. This could lead to unauthorized access to the user's account and sensitive chat history.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Open WebUI's HTML rendering component. The application uses an iFrame to visualize HTML content within chats but employs an insecure sandbox directive: 'allow-scripts allow-forms allow-same-origin'. The inclusion of 'allow-same-origin' alongside 'allow-scripts' allows the sandboxed content to bypass isolation and access the parent window's data, including local storage and authentication tokens. Attackers can exploit this by tricking users into importing malicious chat files, cloning shared chats containing malicious payloads, or uploading files that the UI renders as HTML. A successful exploit allows for the exfiltration of sensitive session tokens via the fetch API. The issue is addressed in version 0.6.5.

Affected products

  • Open WebUI Open WebUI < 0.6.5

Timeline

  • 2026-05-08: disclosed
  • 2026-05-14: advisory
  • 2026-05-14: patched: Fixed in version 0.6.5

References

Related threats