JavaScript Injection Vulnerability in Open WebUI by Open WebUI
CVE-2026-44568

4.8MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44568?

The Open WebUI platform, which enables offline operation for artificial intelligence applications, has a vulnerability in the AccountPending.svelte component. This flaw allows an admin to inject arbitrary JavaScript into the 'Pending User Overlay Content', which can execute in the browser context of any user awaiting account approval who views the overlay page. The improper application of DOMPurify during the rendering process before version 0.9.0 resulted in this security weakness, enabling potential exploitation. This issue has been addressed in version 0.9.0.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.