PT-2025-49146 · Unknown · Open-Webui

CVE-2025-65959

·

Publicado

2025-12-04

·

Atualizado

2025-12-10

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.6.37
Description Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. A Stored Cross-Site Scripting (XSS) issue exists in the Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, which allows them to execute arbitrary JavaScript code and potentially steal session tokens when a victim downloads the note as a PDF. This can be exploited by authenticated users, and unauthenticated external attackers can steal session tokens from users, including administrators and regular users, by sharing specially crafted markdown files. The vulnerability is related to the processing of SVG tags within Markdown files.
Recommendations Versions prior to 0.6.37 should be updated to version 0.6.37.

Exploit

Correção

XSS

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-65959
GHSA-8WVC-869R-XFQF

Produtos afetados

Open-Webui