CVE-2026-44549
EUVD-2026-3063915.05.2026, 22:16
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the sheetjs function sheet_to_html to embed an XSS payload into the generated HTML. This is subsequently added to the DOM unsanitized via @html causing the payload to trigger. This vulnerability is fixed in 0.8.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openwebui | open_webui | 𝑥 < 0.8.0 |
𝑥
= Vulnerable software versions