Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI
Vulnerability Description
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline disposition and no default security headers, enabling script execution in the same origin to steal authentication tokens and achieve account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
open-webui 输入验证错误漏洞
Vulnerability Description
open-webui open-webui是open-webui的机器学习领域中用于人工智能相关应用的用户界面。 open-webui 0.9.5之前版本存在输入验证错误漏洞,该漏洞源于OAuth身份验证流程中通过对图片声明URL MIME类型从文件扩展名而非Content-Type标头进行推断,导致SVG文件绕过配置文件图像验证器并存储为数据URI,经过身份验证的用户访问配置文件图像端点时会收到攻击者控制的SVG内容,可能导致脚本在同一源中执行以窃取身份验证令牌并实现账户接管。
CVSS Information
N/A
Vulnerability Type
N/A