THREAT OPS › Threat News › [GHSA] GHSA-jmc6-2wr8-h3wj (high) — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
[GHSA] GHSA-jmc6-2wr8-h3wj (high) — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
GHSA-jmc6-2wr8-h3wj Severity: high CVE: CVE-2026-87995
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
## Summary Any authenticated user with access to a shared terminal server could get script of their choosing to run in the Open WebUI origin itself. The in-app port preview rendered the content of a previewed port in an iframe whose
Indicators of compromise
- CVE-2026-87995cve
Original source: https://github.com/advisories/GHSA-jmc6-2wr8-h3wj