top of page
perceptive_background_267k.jpg

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch …

Published:

4 August 2026 at 00:00:00

Alert date:

4 August 2026 at 23:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Emerging Technologies

A cross-site scripting vulnerability exists in Open WebUI versions 0.9.0 through 0.11.0 affecting the terminal file-preview functionality. The serveUrl iframe branch incorrectly grants both allow-same-origin and allow-scripts permissions for HTML files served from the application origin. Any authenticated user with access to a configured terminal server can exploit this to execute scripts in the Open WebUI origin context. The attack allows reading victim session tokens from localStorage, enabling full account takeover. If the victim holds admin privileges or workspace.functions access, server-side code execution is also possible. The vulnerability was fixed in version 0.11.0. A GitHub security advisory and corresponding pull request have been published alongside the fix.

Technical details

Mitigation steps:

Affected products:

Open WebUI 0.9.0 - 0.10.x

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page