Junglewise Threat Intelligence

CVE-2026-45317: Open WebUI CSRF via image URL manipulation

CVE-2026-45317 · Severity: medium · CVSS 4.6 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a user interface for interacting with large language models. A security vulnerability allows an attacker to embed malicious links within images, such as profile pictures or shared chat content. When another user views these images, their browser may automatically perform unauthorized actions or leak sensitive information like session cookies and IP addresses. This could lead to account takeover or unauthorized access to private chats and administrative settings.

Technical details

An application-wide Cross-Site Request Forgery (CSRF) and improper input validation vulnerability exists in Open WebUI's image handling. The application fails to validate image URLs and file types, allowing an authenticated attacker to set an image source (e.g., profile pictures, model icons, or images in shared notes/chats) to a malicious endpoint. When a victim views the compromised image, their browser automatically executes a GET request to the attacker-controlled URL. This can be used to leak sensitive headers (cookies, referer, user-agent), perform unauthorized state-changing actions via GET-based API endpoints (like signing out), or conduct internal network scanning. The vulnerability is present in multiple Svelte components including ProfileImage, Navbar, and UserList. A fix is available in version 0.9.3.

Affected products

  • Open WebUI open-webui <= 0.9.2

Timeline

  • 2026-05-09: disclosed: Initial disclosure on GitHub
  • 2026-05-14: advisory: Advisory published and updated

References

Related threats