GHSA-gj27-76gq-5v3p

Suggest an improvement
Source
https://github.com/advisories/GHSA-gj27-76gq-5v3p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gj27-76gq-5v3p
Aliases
Published
2025-03-20T12:32:47Z
Modified
2026-07-07T17:56:11Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Open WebUI stored cross-site scripting (XSS) vulnerability
Details

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the /api/v1/models/add endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-03-21T21:56:34Z",
    "nvd_published_at":  "2025-03-20T10:15:38Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / open-webui

Package

Name
open-webui
View open source insights on deps.dev
Purl
pkg:pypi/open-webui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.3.8

Affected versions

0.*
0.1.124
0.1.125
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json"