PT-2025-12180 · Unknown · Open-Webui

Published

2025-03-20

·

Updated

2025-03-20

·

CVE-2024-7044

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions open-webui/open-webui version 0.3.8
Description A Stored Cross-Site Scripting (XSS) issue exists in the chat file upload functionality. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
Recommendations For open-webui/open-webui version 0.3.8, consider disabling the file upload functionality in the chat until a patch is available to prevent exploitation. Restrict access to uploaded files to minimize the risk of malicious content execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7044
GHSA-J274-M559-CJ4J

Affected Products

Open-Webui