CVE-2026-45318
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, his a
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, his advisory tracks a regression of the original Excel-preview XSS (CVE-2026-44549). The same root cause, XLSX.utils.sheet_to_html() output rendered via {@html excelHtml} without DOMPurify, was reintroduced sometime after v0.8.0 and is exploitable again This vulnerability is fixed in 0.9.3.
MEDIUM · CVSS 5.4
EPSS 0.00012
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0