PT-2026-60119 · Unknown · Open-Webui
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions prior to 0.9.5
Description
A stored cross-site scripting issue exists in the OAuth authentication flow. The system infers the MIME type of the picture claim URL from the file extension instead of the Content-Type header, which allows SVG files to bypass the profile image validator and be stored as data URIs. When authenticated users access the profile image endpoint, they receive attacker-controlled SVG content. Due to the lack of default security headers and the use of inline disposition, scripts can be executed within the same origin, potentially leading to the theft of authentication tokens and account takeover.
Recommendations
Update Open WebUI to version 0.9.5 or later.
Exploit
Fix
DoS
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui