Open WebUI Vulnerability via File Upload Leads to 1-Click RCE Attack
ID: 37f5f63e-3321-5637-ba50-8b321fcfe5e6
STIX ID: report--37f5f63e-3321-5637-ba50-8b321fcfe5e6
Feed Name: cybersecurityNews.com
Open WebUI v0.7.2 contains a critical stored XSS in its profile image upload handler that allows attackers to upload malicious SVGs with Base64-encoded JavaScript; when a user follows the image link the browser executes the script, enabling 1‑click RCE against administrators and silent account takeover and chat-history exfiltration for regular users. The researcher reported the issue on March 10, 2026; the vendor closed the report as a duplicate and did not issue a patch, and a full PoC was published May 8, 2026 — organizations should block image/svg+xml, enforce a strict media-type allowlist, and warn users not to click suspicious Open WebUI links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
