JavaScript Injection Vulnerability in Open WebUI by Open WebUI
CVE-2026-44568
4.8MEDIUM
What is CVE-2026-44568?
The Open WebUI platform, which enables offline operation for artificial intelligence applications, has a vulnerability in the AccountPending.svelte component. This flaw allows an admin to inject arbitrary JavaScript into the 'Pending User Overlay Content', which can execute in the browser context of any user awaiting account approval who views the overlay page. The improper application of DOMPurify during the rendering process before version 0.9.0 resulted in this security weakness, enabling potential exploitation. This issue has been addressed in version 0.9.0.
Affected Version(s)
open-webui < 0.9.0
