Vulnerability Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables stored XSS on the affected chat. This also triggers when the chat is in the shared format. The result is a shareable link containing the payload that can be distributed to any other users on the instance. Version 0.6.44 fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | < 0.6.44 |
Related Weaknesses (CWE)
References
- https://github.com/open-webui/open-webui/blob/6f1486ffd0cb288d0e21f41845361924e0Product
- https://github.com/open-webui/open-webui/security/advisories/GHSA-vjm7-m4xh-7wrcExploitVendor Advisory
FAQ
What is CVE-2026-26193?
CVE-2026-26193 is a vulnerability with a CVSS score of 7.3 (HIGH). Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a re...
How severe is CVE-2026-26193?
CVE-2026-26193 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26193?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.