What is CVE-2026-70486?
CVE-2026-70486 is a vulnerability in the self-hosted AI platform Open WebUI affecting versions 0.9.0 to 0.11.0. The terminal file-preview feature's `serveUrl` iframe branch always granted `allow-same-origin` and `allow-scripts` for HTML files served from the application origin, posing a risk to authenticated users. Users should immediately upgrade to the latest patched version.
Azərbaycanca: CVE-2026-70486 Open WebUI öz-özünə host edilən süni intellekt platformasında 0.9.0-dan 0.11.0 versiyalarına qədər mövcud olan boşluqdur. Terminalda fayl önizləmə funksiyası HTML faylları üçün `allow-same-origin` və `allow-scripts` sandbox atributlarını hər zaman aktiv saxlayaraq autentifikasiya olunmuş istifadəçilərə potensial təhlükə yaradır. Təsirə məruz qalan versiyaları istifadə edənlər təcili olaraq ən son təhlükəsizlik yeniləməsinə keçməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
Which platform is affected by CVE-2026-70486?
CVE-2026-70486 affects the self-hosted AI platform Open WebUI.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.