Openwebui Open Webui — CVE-2026-56398 (Critical)

Date Jul 15, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Openwebui · Open Webui
CVE CVE-2026-56398
Critical vendor advisory CVE-2026-56398

Summary

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 7.3) in Openwebui Open Webui. Patch or mitigate promptly. EPSS percentile: 26%.

Operator check

Review CVE-2026-56398 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.3%; percentile: 26%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.