Impact
Open WebUI contains a stored cross‑site scripting flaw that allows a malicious actor to embed scripts in chat response messages by manually editing chat history and setting the embeds property. The content is woven into an iFrame whose sandbox permits scripts and same‑origin policy despite configuration, resulting in persistent client‑side code execution on any user who views the message.
Affected Systems
The issue affects the open-webui open-webui platform, specifically versions earlier than 0.6.44. Users on a self‑hosted instance that have the ability to modify chat history or create shared chat links are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.3, indicating high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The attack vector is inferred to be via the web interface, requiring an attacker to write or modify chat content or create a shared link. Given its persistence across shared messages, an attacker can disseminate the payload to other users on the same instance.
OpenCVE Enrichment