Open WebUI File Upload Vulnerability Enables 1-Click RCE Attack
ID: bb42e177-3408-5535-aae7-a32912f257a7
STIX ID: report--bb42e177-3408-5535-aae7-a32912f257a7
Feed Name: GBHackers
**Critical stored XSS in Open WebUI (unpatched v0.7.2)** — A profile-image upload flaw allows attackers to upload base64-encoded SVGs that render inline and execute JavaScript in the victim's context, enabling 1-click RCE, creation of reverse-shell-capable tools when an admin is targeted, and exfiltration of local tokens and chat logs; researchers publicly disclosed the issue after a failed private report. Administrators are advised to restrict allowed media types (allowlist JPEG/PNG) or apply patches and avoid clicking external links that redirect to Open WebUI instances. Targeted endpoints include /api/v1/tools/create, /api/v1/chats/all, /api/v1/users/search, and /api/v1/users/[user_id]/profile/image.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
