PT-2025-12200 · Unknown · Open-Webui

Published

2025-03-20

·

Updated

2025-07-21

·

CVE-2024-7990

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions open-webui/open-webui version 0.3.8
Description A stored cross-site scripting (XSS) issue exists, allowing an attacker to inject malicious scripts through the /api/v1/models/add endpoint, where the model description field is improperly sanitized. This can lead to arbitrary code execution by any user, including administrators.
Recommendations For open-webui/open-webui version 0.3.8, consider disabling access to the /api/v1/models/add endpoint until a patch is available, or ensure proper sanitization of the model description field to prevent script injection.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7990
GHSA-GJ27-76GQ-5V3P

Affected Products

Open-Webui