PT-2025-12200 · Unknown · Open-Webui

CVE-2024-7990

·

Published

2025-03-20

·

Updated

2026-07-07

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions open-webui/open-webui version 0.3.8
Description A stored cross-site scripting (XSS) issue exists, allowing an attacker to inject malicious scripts through the /api/v1/models/add endpoint, where the model description field is improperly sanitized. This can lead to arbitrary code execution by any user, including administrators.
Recommendations For open-webui/open-webui version 0.3.8, consider disabling access to the /api/v1/models/add endpoint until a patch is available, or ensure proper sanitization of the model description field to prevent script injection.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7990
GHSA-GJ27-76GQ-5V3P
PYSEC-2026-1734

Affected Products

Open-Webui