We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the SameSite attribute set to lax for authentication and lacks CSRF tokens. This allows an attacker to craft a malicious HTML that, when accessed by a victim, can modify the Python code of an existing pipeline and execute arbitrary code with the victim's privileges.
Reserved 2024-08-14 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-352 Cross-Site Request Forgery (CSRF)
huntr.com/bounties/9350a68d-5f33-4b3d-988b-81e778160ab8
Support options