Open WebUI是Open WebUI开源的一个可扩展、功能丰富、用户友好的自托管 WebUI。 Open WebUI 0.6.34及之前版本存在跨站脚本漏洞,该漏洞源于将提示正文分配给DOM接收器innerHtml时未进行清理,可能导致跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-webui | open-webui | < 0.6.35 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE | https://github.com/AlphabugX/CVE-2025-64495-POC | POC Details |
| 2 | CVE-2025-64495 | https://github.com/B1ack4sh/Blackash-CVE-2025-64495 | POC Details |
| 3 | CVE-2025-64495 | https://github.com/Ashwesker/Blackash-CVE-2025-64495 | POC Details |
No comments yet