Skip to content

Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin

High severity GitHub Reviewed Published Aug 2, 2026 in open-webui/open-webui • Updated Aug 4, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts