CVE-2026-87995 | open-webui Open WebUI up to 0.11.0 PortPreview PortPreview.svelte cross-domain policy
A vulnerability has been found in open-webui Open WebUI up to 0.11.0 and classified as problematic. Impacted is an unknown function of the file src/lib/components/chat/FileNav/PortPreview.svelte of the component PortPreview. Performing a manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is identified as CVE-2026-87995. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More