CVE-2026-26192 | open-webui Open WebUI up to 0.6.x Chat cross site scripting (GHSA-xc8p-9rr6-97r2)
A vulnerability was found in open-webui Open WebUI up to 0.6.x. It has been classified as problematic. This affects an unknown part of the component Chat. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-26192. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.