| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6916 | A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution. |
Github GHSA |
GHSA-gj27-76gq-5v3p | Open WebUI stored cross-site scripting (XSS) vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| CPEs | ||
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| References |
|
|
| Metrics |
cvssV3_0
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Mon, 21 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| CPEs | cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution. | |
| Title | Stored Cross-Site Scripting in open-webui/open-webui | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2026-08-13T14:41:16.989Z
Reserved: 2024-08-19T21:19:22.433Z
Link: CVE-2024-7990
Updated: 2025-03-20T17:50:49.636Z
Status : Rejected
Published: 2025-03-20T10:15:38.503
Modified: 2026-08-13T15:19:13.250
Link: CVE-2024-7990
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:01:21Z
No weakness.
EUVD
Github GHSA