CVE-2026-26193 | open-webui Open WebUI up to 0.6.43 Response Message cross site scripting (GHSA-vjm7-m4xh-7wrc)
A vulnerability was found in open-webui Open WebUI up to 0.6.43. It has been declared as problematic. This vulnerability affects unknown code of the component Response Message Handler. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-26193. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.