Improper Restriction of Rendered UI Layers or Frames Affecting open-webui package, versions [0.8.11,0.11.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-OPENWEBUI-20158694
  • published27 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-87995  (opens in a new tab)
CWE-1021  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.11.1 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames in the PortPreview process. An attacker can gain access to session tokens and take over user accounts by serving malicious scripts on a terminal server port and convincing a victim to preview that port within the application. This is only exploitable if at least one terminal server is configured and reachable by both attacker and victim, the attacker has a normal authenticated account with access to the terminal connection, the victim opens the port list and clicks the attacker's port, and default security headers (TERMINAL_PROXY_HEADERS and CONTENT_SECURITY_POLICY) remain unset.

CVSS Base Scores

version 4.0
version 3.1