Executive brief
Open WebUI, a user interface for large language models, is vulnerable to a security flaw where malicious Office documents (Excel, Word) can execute unauthorized code in a user's browser. If an attacker uploads a specially crafted file, any user who previews that file within the application could have their session hijacked or their data stolen. This occurs because the application fails to properly clean the content of these files before displaying them as HTML.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Open WebUI due to a regression and incomplete coverage of HTML sanitization. The application uses Svelte's {@html} directive to render HTML generated from user-uploaded Office documents (via XLSX.utils.sheet_to_html and similar converters) without passing the output through DOMPurify. This affects three specific sinks: fileOfficeHtml in FilePreview.svelte, and excelHtml and docxHtml in FileItemModal.svelte. An authenticated attacker can upload a malicious document containing JavaScript payloads; when another user previews the file, the payload executes in their browser context, potentially leading to session hijacking or account takeover. The issue is fixed in version 0.9.3.
Affected products
- Open WebUI open-webui <= 0.9.2
Timeline
- 2026-05-09: disclosed: Vulnerability reported to vendor
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-14: patched: Fixed in version 0.9.3