Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library).
This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the global banner.
Recommendation
Update the open-webui package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.7.2
- Patched version(s): 0.8.0
References
Could your website be exposed too?
SmartScanner can check your website for Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order and gives you actionable findings to investigate.
Start a free scanRelated Issues
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF - CVE-2025-65959


