Script Injection Vulnerability in Open WebUI by Open WebUI
CVE-2026-45303

7.7HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45303?

Open WebUI, a self-hosted artificial intelligence platform, was found to be vulnerable due to improper handling of content within its HTML rendering feature. Prior to version 0.6.5, the application allowed for script injection through its frontend that visualizes HTML content of chats. The affected functionality permitted the execution of scripts within an iFrame, despite being sandboxed with the allow-scripts, allow-forms, and allow-same-origin directives. This resulted in a significant security risk, as the sandbox's restrictions were largely ineffective, allowing malicious actors to potentially access sensitive data from the parent context. The issue has been addressed in version 0.6.5.

Affected Version(s)

open-webui < 0.6.5

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.