Openwebui Open Webui — CVE-2026-56398 (Critical)
Summary
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 7.3) in Openwebui Open Webui. Patch or mitigate promptly. EPSS percentile: 26%.
Operator check
Review CVE-2026-56398 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.3%; percentile: 26%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.