CVE-2026-45303
CVE-2026-45303 is a high-severity vulnerability in Openwebui Open Webui with a CVSS 3.x base score of 7.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-79.
Key facts
- Severity: High (CVSS 3.x base score 7.7)
- EPSS exploit prediction: 0% (21st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-30654
- Weakness: CWE-79
- Affected product: Openwebui Open Webui
- Published:
- Last modified:
Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend provides a function to visualize the HTML content of a current chat. The content is embedded in an iFrame with the allow-scripts allow-forms allow-same-origin sandbox directive. This means that the content is placed in a sandbox but with permission to execute scripts and access the parent’s data (e.g., local storage). As a result, only a few functions are restricted (e.g., displaying an alert box), but in effect, the sandbox attribute is largely nullified. This vulnerability is fixed in 0.6.5.
Frequently asked questions
- What is CVE-2026-45303?
- Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend provides a function to visualize the HTML content of a current chat. The content is embedded in an iFrame with the allow-scripts allow-forms allow-same-origin sandbox directive. This means that the content is placed in a sandbox but with permission to execute scripts and access the parent’s data (e.g., local storage). As a result, only a few functions are restricted (e.g., displaying an alert box), but in effect, the sandbox attribute is largely nullified. This vulnerability is fixed in 0.6.5.
- How severe is CVE-2026-45303?
- CVE-2026-45303 has a CVSS 3.x base score of 7.7, rated high severity. It is exploitable over network with high attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-45303 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (21st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-45303?
- CVE-2026-45303 affects Openwebui Open Webui. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-45303?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-45303 have an EU (EUVD) identifier?
- Yes. CVE-2026-45303 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-30654.
- When was CVE-2026-45303 published?
- CVE-2026-45303 was published on 2026-05-15 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
More vulnerabilities in Openwebui Open Webui
- CVE-2026-44551 — Critical (CVSS 9.1): Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the…
- CVE-2024-8017 — Critical (CVSS 9.0): An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs…
- CVE-2024-7044 — High (CVSS 8.9): A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui…
- CVE-2026-45672 — High (CVSS 8.8): Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the…
- CVE-2024-7043 — High (CVSS 8.8): An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files.…
- CVE-2024-6707 — High (CVSS 8.8): Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path…
All CVEs affecting Openwebui Open Webui →
Other CWE-79 (Cross-site Scripting (XSS)) vulnerabilities
- CVE-2026-106102 — Critical (CVSS 10.0): Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only…
- CVE-2026-59167 — Critical (CVSS 10.0): SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11,…
- CVE-2026-85061 — Critical (CVSS 10.0): MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in…
- CVE-2025-49410 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC…
- CVE-2024-47875 — Critical (CVSS 10.0): DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to…
- CVE-2024-6886 — Critical (CVSS 10.0): Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea…
Browse all CWE-79 (Cross-site Scripting (XSS)) vulnerabilities →