{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/open-webui-0.8.11-0.11.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openwebui:open_webui:0.8.11:*:*:*:*:*:*:*","cpe:2.3:a:openwebui:open_webui:0.11.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-87995"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open WebUI (0.8.11-0.11.0)","Open WebUI (0.9.6 - 0.11.0)","Open WebUI (0.10.0-0.11.0)","Open WebUI (\u003c 0.11.1)","Open WebUI (0.9.0 - 0.11.0)","Open WebUI (\u003e= 0.6.41, \u003c 0.11.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","session-theft","web-application","ssrf","cve-2026-87996","vulnerability","denial-of-service","cloud","oidc","authentication-bypass","sqlite","cve-2026-87016"],"_cs_type":"advisory","_cs_vendors":["Open WebUI"],"content_html":"\u003cp\u003eOpen WebUI versions 0.8.11 through 0.11.0 contain a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2026-87995) within the terminal port-preview component. The application renders content from a terminal connection inside an iframe; however, the sandbox attribute for this iframe incorrectly included the \u003ccode\u003eallow-same-origin\u003c/code\u003e directive. Because the terminal proxy is served from the same origin as the primary application, this configuration effectively disables iframe isolation.\u003c/p\u003e\n\u003cp\u003eAn authenticated attacker with access to a shared terminal server can host a malicious HTML page on a port. When an unsuspecting user views this port via the Open WebUI terminal preview, the attacker-supplied script executes within the application origin. This permits the script to access \u003ccode\u003elocalStorage\u003c/code\u003e, extract sensitive session tokens, and perform actions on behalf of the victim, leading to full account takeover. The vulnerability persists unless the user has manually configured restrictive Content Security Policy (CSP) headers or utilized a terminal connection with an external URL, which forces a cross-origin boundary.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains authenticated access to a shared terminal server environment managed by the Open WebUI instance.\u003c/li\u003e\n\u003cli\u003eAttacker deploys a malicious HTML file or script on a reachable port within that terminal server environment.\u003c/li\u003e\n\u003cli\u003eAttacker waits for a victim user (potentially an administrator) to open the Open WebUI file navigator.\u003c/li\u003e\n\u003cli\u003eVictim user navigates to the port list and selects the attacker-controlled port for preview.\u003c/li\u003e\n\u003cli\u003eOpen WebUI renders the attacker's content within an iframe using the insecure \u003ccode\u003eallow-same-origin\u003c/code\u003e and \u003ccode\u003eallow-scripts\u003c/code\u003e sandbox flags.\u003c/li\u003e\n\u003cli\u003eMalicious script executes in the parent application context and accesses \u003ccode\u003ewindow.parent.localStorage\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eScript exfiltrates the victim's session token to an attacker-controlled external server.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen session token to assume the victim's identity and perform unauthorized operations, such as executing server-side code via Functions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in total account takeover of the victim. If the compromised victim holds administrative privileges or permissions related to \u003ccode\u003eworkspace.functions\u003c/code\u003e, the attacker can escalate to server-side code execution. The attack is limited to deployments where \u003ccode\u003eTERMINAL_SERVER_CONNECTIONS\u003c/code\u003e are configured and shared between users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpgrade Open WebUI to version 0.11.1 or later immediately to resolve CVE-2026-87995. Ensure that the \u003ccode\u003eterminalPreviewAllowSameOrigin\u003c/code\u003e user setting remains disabled, which is the default behavior in the patched version. For administrators who cannot upgrade immediately, verify that a restrictive Content Security Policy (CSP) is applied via the \u003ccode\u003eTERMINAL_PROXY_HEADERS\u003c/code\u003e configuration to mitigate the risk of script exfiltration.\u003c/p\u003e\n","date_modified":"2026-09-11T00:54:51Z","date_published":"2026-09-10T18:53:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-open-webui-xss/","summary":"An insecure sandbox configuration in the Open WebUI terminal port preview feature allows authenticated users to execute arbitrary JavaScript in the application's origin, leading to session token theft and account takeover.","title":"Open WebUI Same-Origin XSS via Terminal Port Preview","url":"https://feed.craftedsignal.io/briefs/2026-09-open-webui-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Open WebUI (0.8.11-0.11.0)","version":"https://jsonfeed.org/version/1.1"}