Cross-Site Scripting Vulnerability in Open WebUI Affects Self-Hosted AI Platform
CVE-2026-70486
8.2HIGH
What is CVE-2026-70486?
Open WebUI, a self-hosted AI platform, contains a vulnerability that allows authenticated users to execute scripts in previewed HTML files. This occurs due to insecure iframe settings—enabling 'allow-same-origin' and 'allow-scripts'—from versions 0.9.0 to 0.11.0. Consequently, an attacker with access to the terminal server can read a victim's session token from localStorage, potentially taking over the account. If the compromised user holds admin privileges, there is a risk of server-side code execution. This security flaw has been addressed in version 0.11.0.
Affected Version(s)
open-webui >= 0.9.0, < 0.11.0
