{"id":"CVE-2026-56398","aliases":["GHSA-3wgj-c2hg-vm6q"],"url":"https://o3.security/vulnerability/CVE-2026-56398","summary":"Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI","details":"Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.","published":"2026-07-15T11:25:30.722Z","modified":"2026-08-07T11:51:35.774489737Z","cvss":null,"epss":{"score":0.00416,"percentile":0.34302,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"open-webui","fixedVersion":"0.9.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56398.json"},{"type":"ADVISORY","url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-3wgj-c2hg-vm6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56398"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/open-webui-stored-cross-site-scripting-via-oauth-picture-claim-svg-data-uri"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:35.774489737Z"}}