Cross-Site Request Forgery in Open WebUI Affects Image Upload Functionality
CVE-2026-45317

4.6MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45317?

Open WebUI, a self-hosted artificial intelligence platform, had a vulnerability in its image uploading functionality prior to version 0.9.3. The flaw allowed attackers to exploit cross-site request forgery (CSRF), enabling them to set malicious image URLs. When authenticated users viewed these images, they unknowingly sent GET requests to the attacker-controlled endpoints. This could lead to unauthorized actions being performed on behalf of the users, including potential cookie theft, denial of service, or other malicious activities. The issue has been resolved in version 0.9.3.

Affected Version(s)

open-webui < 0.9.3

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.