Executive brief
Open WebUI, a user interface for interacting with AI models, is vulnerable to a security flaw where low-privileged users can upload malicious files. If an administrator views one of these files, an attacker could gain full control over the administrator's account. This could lead to unauthorized access to sensitive data or the ability to execute commands on the underlying server.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Open WebUI's file upload functionality via the `/api/v1/files/` endpoint. Low-privileged users can bypass basic sanitization by including additional HTML tags (like `<h1>`) alongside a `<script>` tag in an uploaded HTML file. While authorization checks restrict file visibility to the uploader and administrators, an attacker can trick an administrator into viewing the file's content at `/api/v1/files/<file_id>/content/html`. Upon execution, the JavaScript can steal the administrator's session token, potentially leading to account takeover and subsequent remote code execution (RCE) via administrative functions. This issue is fixed in version 0.6.6.
Affected products
- Open WebUI Open WebUI < 0.6.6
Timeline
- 2025-05-05: disclosed
- 2025-05-05: patched: Fixed in version 0.6.6
- 2026-07-07: advisory