PT-2025-12200 · Unknown · Open-Webui
Published
2025-03-20
·
Updated
2025-07-21
·
CVE-2024-7990
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
open-webui/open-webui version 0.3.8
Description
A stored cross-site scripting (XSS) issue exists, allowing an attacker to inject malicious scripts through the
/api/v1/models/add endpoint, where the model description field is improperly sanitized. This can lead to arbitrary code execution by any user, including administrators.Recommendations
For open-webui/open-webui version 0.3.8, consider disabling access to the
/api/v1/models/add endpoint until a patch is available, or ensure proper sanitization of the model description field to prevent script injection.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui