XSS Vulnerability in Open WebUI Affects Self-Hosted AI Platforms
CVE-2026-45318

5.4MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45318?

A Cross-Site Scripting (XSS) vulnerability exists in Open WebUI prior to version 0.9.3 due to the unsanitized output produced by XLSX.utils.sheet_to_html(). This vulnerability reintroduces a previously resolved issue where the Excel-preview functionality allows for the injection of malicious scripts. Without the use of DOMPurify, an attacker can exploit this vulnerability to execute arbitrary JavaScript in the context of the user’s session, potentially compromising sensitive data and user accounts. Users are advised to upgrade to version 0.9.3 or later to mitigate this risk.

Affected Version(s)

open-webui < 0.9.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.