Executive brief
Open WebUI, a user interface for large language models, is vulnerable to a security flaw where malicious users can upload specially crafted profile pictures. If another user or administrator views this profile picture, an attacker could execute malicious scripts in their browser. This could lead to the theft of login tokens and full account takeover of any user, including administrators.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Open WebUI versions prior to 0.8.0 due to a lack of MIME-type validation on the 'profile_image_url' field. Attackers can provide a 'data:image/svg+xml;base64' URI containing malicious JavaScript. When the application serves this image via the '/api/v1/users/{user_id}/profile/image' endpoint, it uses a user-controlled 'media_type' in a 'StreamingResponse' with 'Content-Disposition: inline'. This causes the script to execute in the application's origin, allowing for JWT theft from localStorage and full account takeover. The vulnerability is fixed in version 0.8.0 by implementing strict validation for allowed image types.
Affected products
- Open WebUI open-webui < 0.8.0
Timeline
- 2025-04-17: other: Initial discovery of data:text/html path by raresvis
- 2026-01-09: other: Discovery of origin-XSS path by Gh05t666nero
- 2026-02-11: patched: Fix committed in version 0.8.0
- 2026-05-14: advisory: Advisory published