PT-2026-41162 · Unknown · Open-Webui

CVE-2026-45299

·

Published

2026-03-08

·

Updated

2026-07-13

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.8.0
Description The profile image url field on the user profile update form accepts arbitrary data: URI values without MIME-type validation, leading to Cross-Site Scripting (XSS). This occurs because the application fails to validate the media type of the provided URI. One attack vector involves using data:text/html;base64,..., which executes scripts when a user opens the image in a new browser tab. A more severe vector utilizes data:image/svg+xml;base64,... via the 'GET /api/v1/users/{user id}/profile/image' endpoint. In this case, the get user profile image by id() function returns a response with a user-controlled media type, allowing SVG-embedded scripts to execute within the application origin. This can enable the theft of JSON Web Tokens (JWT) from localStorage and result in full account takeover of any user, including administrators.
Recommendations Update to version 0.8.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07136
CVE-2026-45299
GHSA-6GH2-Q7CP-9QF6
PYSEC-2026-2708

Affected Products

Open-Webui