CVE-2026-87995
Undergoing Analysis Undergoing Analysis - In Progress

XSS in Open WebUI Terminal Port Preview

Vulnerability report for CVE-2026-87995, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts and allow-same-origin. Because the terminal proxy serves that content from the Open WebUI origin, an authenticated user with access to a shared terminal server could host script on a previewed port and take over a victim's account when the victim opened the preview. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open_webui open_webui From 0.8.11 (inc) to 0.11.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-1021 The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Open WebUI versions 0.8.11 to 0.11.1 had a vulnerability in the FileNav/PortPreview.svelte component. It used an iframe with both allow-scripts and allow-same-origin sandbox attributes. Since the terminal proxy served content from the Open WebUI origin, an attacker could host malicious scripts on a previewed port. When a victim opened the preview, the attacker could take over their account.

Detection Guidance

This vulnerability can be detected by checking the version of Open WebUI installed on your system. If the version is between 0.8.11 and 0.11.0, it is vulnerable. Run the command: open_webui --version to check the installed version.

Impact Analysis

If you used Open WebUI versions between 0.8.11 and 0.11.1, an attacker with access to a shared terminal server could trick you into opening a malicious port preview. This could lead to unauthorized account takeover, allowing the attacker to access your data or perform actions on your behalf.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations using affected versions may face compliance breaches, potential fines, and reputational damage.

Mitigation Strategies

Immediately upgrade Open WebUI to version 0.11.1 or later. Remove or restrict access to shared terminal servers until the upgrade is completed. Review user permissions to ensure only trusted users have access to terminal features.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87995. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart