{"id":"CVE-2026-54011","aliases":["GHSA-v8qj-hxv7-mgvv","PYSEC-2026-2759"],"url":"https://o3.security/vulnerability/CVE-2026-54011","summary":"Open WebUI: Stored XSS in Mermaid Markdown Preview","details":"## Summary\n\nOpen WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using `innerHTML`.\n\nBecause Mermaid is configured with `securityLevel: 'loose'`, attacker-controlled Mermaid content can be rendered unsafely in this flow. A working payload was validated through the Markdown preview path, resulting in JavaScript execution in the victim’s browser under the application origin.\n\nThis is a confirmed stored XSS vulnerability reachable through normal product functionality.\n\n## Affected Version\n\n- `main`\n- Reproduced on `v0.8.12`\n\n## Affected Code\n\nMermaid is initialized in permissive mode:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/utils/index.ts#L1698\nThe file preview path renders Mermaid output and injects the returned SVG into the DOM:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/components/chat/FileNav/FilePreview.svelte#L133\n\n## Impact\n\nA successful exploit allows JavaScript execution in the victim’s browser under the Open WebUI origin when a malicious Markdown file is opened in the preview panel.\n\n## PoC\n\nA malicious `.md` file containing the follwowing contents can be used to trigger the bug:\n````\n```mermaid\nflowchart LR\n  A[click me]\n  click A href \"javascript:alert(document.domain)\" \"x\"\n```\n````\nSteps to reproduce: \n1- Create a new chat \n2- Enable Code Interpreter and browse and upload the file with `.md` extension. \n<img width=\"331\" height=\"258\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bce2b754-56d1-4da1-90a9-22bcb93269f2\" />\n3- Clicking on the file, and clicking `click me` should pop an alert\n<img width=\"1103\" height=\"485\" alt=\"image\" src=\"https://github.com/user-attachments/assets/18754486-799b-434e-a2fc-dd7c09956a29\" />\n \n\n## Remediation\n\nSince `mermaid` has `DOMPurify` as a built-in, it is recommended to use the `strict` mode instead of `loose`.","published":"2026-06-23T16:47:43.581Z","modified":"2026-08-12T03:51:26.937272581Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":{"score":0.00336,"percentile":0.26699,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"open-webui","fixedVersion":"0.9.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54011.json"},{"type":"ADVISORY","url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-v8qj-hxv7-mgvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54011"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v8qj-hxv7-mgvv"},{"type":"PACKAGE","url":"https://github.com/open-webui/open-webui"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2759.yaml"},{"type":"WEB","url":"https://pypi.org/project/open-webui"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.937272581Z"}}