THREAT OPS › Threat News › [GHSA] GHSA-3xpf-xq7r-v8c5 (high) — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
[GHSA] GHSA-3xpf-xq7r-v8c5 (high) — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
GHSA-3xpf-xq7r-v8c5 Severity: high CVE: CVE-2026-70486
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
## Summary Any authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always gran
MITRE ATT&CK techniques
- Malicious FileT1204.002
Indicators of compromise
- CVE-2026-70486cve
Original source: https://github.com/advisories/GHSA-3xpf-xq7r-v8c5