Executive brief
Open WebUI, a user interface for large language models, contains a security flaw in its banner notification system. A user with administrative privileges can create a malicious banner that, when clicked by other administrators, executes unauthorized code in their browser. This could allow an attacker to hijack the sessions of high-level 'Super Admins,' effectively taking full control of the entire system and bypassing security measures like multi-factor authentication.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Banner component of Open WebUI (specifically in `src/lib/components/common/Banner.svelte`). The root cause is an improper sanitization sequence where `DOMPurify.sanitize()` is called before the `marked` library parses the markdown. Because markdown link syntax like `[text](javascript:...)` is treated as plain text by DOMPurify, it passes through unsanitized; the `marked` library then converts it into an executable HTML anchor tag. An attacker with administrative privileges can use this to inject malicious JavaScript into global banners. When a Primary Admin (Super Admin) interacts with the banner, the script executes, potentially allowing the attacker to steal session tokens and escalate privileges. This is fixed in version 0.8.0 by reversing the order of operations.
Affected products
- Open WebUI open-webui <= 0.7.2
Timeline
- 2026-05-11: disclosed: Initial report by POV9en
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-14: patched: Fixed in version 0.8.0