Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files uploaded by low-privileged users can only be viewed by admins or themselves, limiting the impact of this vulnerability. A link to such a file can be sent to an admin, and if clicked, will give the low-privileged user complete control over the admin's account, ultimately enabling RCE via functions. Version 0.6.6 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openwebui
Openwebui open Webui |
|
CPEs | cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* | |
Vendors & Products |
Openwebui
Openwebui open Webui |
|
Metrics |
cvssV3_1
|
Mon, 05 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files uploaded by low-privileged users can only be viewed by admins or themselves, limiting the impact of this vulnerability. A link to such a file can be sent to an admin, and if clicked, will give the low-privileged user complete control over the admin's account, ultimately enabling RCE via functions. Version 0.6.6 contains a fix for the issue. | |
Title | Open WebUI vulnerable to limited stored XSS vila uploaded html file | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-05T18:45:29.718Z
Updated: 2025-05-05T18:59:48.168Z
Reserved: 2025-04-24T21:10:48.175Z
Link: CVE-2025-46571

Updated: 2025-05-05T18:59:38.283Z

Status : Analyzed
Published: 2025-05-05T19:15:57.050
Modified: 2025-06-17T20:18:30.580
Link: CVE-2025-46571

No data.