A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution.
History

Mon, 21 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Openwebui
Openwebui open Webui
CPEs cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
Vendors & Products Openwebui
Openwebui open Webui

Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution.
Title Stored Cross-Site Scripting in open-webui/open-webui
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 8.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:08:55.590Z

Updated: 2025-03-20T19:00:39.768Z

Reserved: 2024-08-19T21:19:22.433Z

Link: CVE-2024-7990

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:49.636Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:38.503

Modified: 2025-07-21T20:07:26.380

Link: CVE-2024-7990

cve-icon Redhat

No data.