An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.
History

Mon, 21 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Openwebui
Openwebui open Webui
CPEs cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
Vendors & Products Openwebui
Openwebui open Webui

Thu, 20 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.
Title Cross-site Scripting (XSS) in open-webui/open-webui
Weaknesses CWE-79
References
Metrics cvssV3_0

{'score': 9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:11:31.223Z

Updated: 2025-03-20T14:19:30.503Z

Reserved: 2024-08-20T17:06:56.123Z

Link: CVE-2024-8017

cve-icon Vulnrichment

Updated: 2025-03-20T14:19:08.714Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:38.763

Modified: 2025-07-21T20:08:16.507

Link: CVE-2024-8017

cve-icon Redhat

No data.