Remote Code Execution Vulnerability in Open WebUI by Open WebUI
CVE-2025-46571
5.3MEDIUM
What is CVE-2025-46571?
Open WebUI, an offline artificial intelligence platform, has a vulnerability that allows low privileged users to upload HTML files containing JavaScript code via the '/api/v1/files/' endpoint. When these files are accessed by an admin, they can inadvertently execute malicious JavaScript, potentially leading to complete control over the admin's account and the ability to execute arbitrary code. This issue is addressed in version 0.6.6 of the platform, which contains the necessary fixes to prevent such exploitation.
Affected Version(s)
open-webui < 0.6.6