Junglewise Threat Intelligence

CVE-2026-45346: Open WebUI stored XSS in SVG renderer

CVE-2026-45346 · Severity: medium · CVSS 4 · Published 2026-05-15

Technologies: Open WebUI Open-Webui.

Executive brief

Open WebUI, a popular interface for interacting with large language models, contains a security flaw in how it handles generated images. An attacker can create a conversation containing a malicious image and share it with other users or administrators. If a victim views the shared conversation, the attacker can execute code in their browser to steal sensitive information or take over their account.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Open WebUI's SVG renderer. The application fails to properly neutralize script-related HTML tags (CWE-80) when processing SVG code within chat threads. An attacker can trigger the generation of an SVG, manually edit the code to include a malicious payload (e.g., an <img> tag with an onerror handler), and save it. When this thread is shared and viewed by another user or administrator, the payload executes in the context of the application domain. This can lead to session hijacking or sensitive data extraction. The issue is fixed in version 0.6.31.

Affected products

  • Open WebUI open-webui < 0.6.31

Timeline

  • 2026-05-09: disclosed: Vulnerability reported to vendor
  • 2026-05-14: advisory: GitHub Advisory published
  • 2026-05-14: patched: Fixed in version 0.6.31

References