THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jmc6-2wr8-h3wj (high) — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

[GHSA] GHSA-jmc6-2wr8-h3wj (high) — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

medgithub_advisoriesPublished 2026-09-10

GHSA-jmc6-2wr8-h3wj Severity: high CVE: CVE-2026-87995

Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

## Summary Any authenticated user with access to a shared terminal server could get script of their choosing to run in the Open WebUI origin itself. The in-app port preview rendered the content of a previewed port in an iframe whose

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jmc6-2wr8-h3wj