Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
- Severity:
- High
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library).
This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the global banner.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.7.2
- Patched version(s): 0.8.0
References
Related Issues
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959
You might also like:
- Tags:
- npm
- open-webui
Anything's wrong? Let us know Last updated on May 19, 2026


