Impact
open-webui before 0.3.14 suffers from a CORS misconfiguration that permits any origin to access authenticated requests on the /api/v1/functions endpoint. The likely attack vector is that an attacker can create a malicious cross‑site request from a site under their control. If an admin user of the open‑webui instance visits that site while authenticated, the victim’s browser will send the request to the API with the user’s credentials, allowing the attacker to send payloads that are executed on the server. This flaw results in arbitrary code execution with the privileges of the targeted account, potentially allowing full system compromise.
Affected Systems
The vulnerability affects the open‑webui project, specifically versions prior to 0.3.14. Administrators using open‑webui 0.3.13 or earlier are at risk. The product is distributed under the open‑webui:open‑webui CPE identifier.
Risk and Exploitability
The CVSS score of 9 indicates high severity, and the EPSS score of < 1% suggests a low probability of exploitation at the time of this analysis. The flaw is not listed in the CISA KEV catalog. The likely attack vector requires an attacker‑controlled website and a privileged user to visit that site while authenticated. Because the vulnerability can be triggered without needing arbitrary code on the client or elevated network privileges, the risk to the installed environment remains high if patched action is delayed.
OpenCVE Enrichment