An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HOpenwebui Open Webui
APPOpenwebui≤ 0.3.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2026-56400CRITICAL9.0PL ✓same product
open-webui: RCE przez błędną konfigurację CORS i brak walidacji sesji
CVE-2026-44551CRITICAL9.1PL ✓same product
Open WebUI: pominięcie uwierzytelnienia LDAP przez puste hasło (Auth Bypass)
CVE-2026-56398HIGH8.5PL ✓same product
Open WebUI: stored XSS w przepływie OAuth poprzez SVG jako data URI
CVE-2026-59214HIGH7.3PL ✓same product
Stored XSS w Open WebUI umożliwia nieautoryzowany dostęp do endpointów admina
CVE-2026-59216HIGH7.7PL ✓same product
Open WebUI: nieautoryzowane wykonanie kodu w cudzej sesji przez Socket.IO