Stored Cross-Site Scripting in Open WebUI Banner Component
CVE-2026-45665
8.1HIGH
What is CVE-2026-45665?
Open WebUI, an offline artificial intelligence platform, contains a vulnerability in its Banner component where improper sanitization allows attackers to inject malicious scripts. This occurs due to the incorrect execution order of sanitization libraries, which enables an attacker with administrative privileges to embed a harmful payload in the global banner. Such a payload is rendered across user sessions, including those of Super Admins, leading to a risk of session token theft and privilege escalation. This significant flaw was addressed in version 0.8.0.
Affected Version(s)
open-webui < 0.8.0
