CRITICAL🇵🇱 Wersja polska

CVE-2024-8017

CVSS 9.0v3.0pub. 2025-03-20upd. 2025-07-21

An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Openwebui Open Webui

    APP
    Openwebui
    ≤ 0.3.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-56400CRITICAL9.0PL ✓same product

open-webui: RCE przez błędną konfigurację CORS i brak walidacji sesji

CVE-2026-44551CRITICAL9.1PL ✓same product

Open WebUI: pominięcie uwierzytelnienia LDAP przez puste hasło (Auth Bypass)

CVE-2026-56398HIGH8.5PL ✓same product

Open WebUI: stored XSS w przepływie OAuth poprzez SVG jako data URI

CVE-2026-59214HIGH7.3PL ✓same product

Stored XSS w Open WebUI umożliwia nieautoryzowany dostęp do endpointów admina

CVE-2026-59216HIGH7.7PL ✓same product

Open WebUI: nieautoryzowane wykonanie kodu w cudzej sesji przez Socket.IO