XSS Vulnerability in Open WebUI Affects User Profile Image Updates
CVE-2026-45299

5.4MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45299?

Open WebUI, an offline AI platform, previously allowed arbitrary URI inputs in the profile_image_url field without proper MIME-type validation. This flaw posed a significant XSS risk during user profile updates, enabling potential exploit scenarios. The vulnerability has been addressed in version 0.8.0, enhancing the overall security of the application.

Affected Version(s)

open-webui < 0.8.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.