Stored Cross-Site Scripting in Open WebUI Banner Component
CVE-2026-45665

8.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45665?

Open WebUI, an offline artificial intelligence platform, contains a vulnerability in its Banner component where improper sanitization allows attackers to inject malicious scripts. This occurs due to the incorrect execution order of sanitization libraries, which enables an attacker with administrative privileges to embed a harmful payload in the global banner. Such a payload is rendered across user sessions, including those of Super Admins, leading to a risk of session token theft and privilege escalation. This significant flaw was addressed in version 0.8.0.

Affected Version(s)

open-webui < 0.8.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.