PT-2026-60119 · Unknown · Open-Webui

·

CVE-2026-56398

·

Published

2026-05-14

·

Updated

2026-07-15

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.9.5
Description A stored cross-site scripting issue exists in the OAuth authentication flow. The system infers the MIME type of the picture claim URL from the file extension instead of the Content-Type header, which allows SVG files to bypass the profile image validator and be stored as data URIs. When authenticated users access the profile image endpoint, they receive attacker-controlled SVG content. Due to the lack of default security headers and the use of inline disposition, scripts can be executed within the same origin, potentially leading to the theft of authentication tokens and account takeover.
Recommendations Update Open WebUI to version 0.9.5 or later.

Exploit

Fix

DoS

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56398
GHSA-3WGJ-C2HG-VM6Q

Affected Products

Open-Webui