logo

Open WebUI File Upload Vulnerability Enables 1-Click RCE Attack

ID: bb42e177-3408-5535-aae7-a32912f257a7

STIX ID: report--bb42e177-3408-5535-aae7-a32912f257a7

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Divya

...
...

**Critical stored XSS in Open WebUI (unpatched v0.7.2)** — A profile-image upload flaw allows attackers to upload base64-encoded SVGs that render inline and execute JavaScript in the victim's context, enabling 1-click RCE, creation of reverse-shell-capable tools when an admin is targeted, and exfiltration of local tokens and chat logs; researchers publicly disclosed the issue after a failed private report. Administrators are advised to restrict allowed media types (allowlist JPEG/PNG) or apply patches and avoid clicking external links that redirect to Open WebUI instances. Targeted endpoints include /api/v1/tools/create, /api/v1/chats/all, /api/v1/users/search, and /api/v1/users/[user_id]/profile/image.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.