Cross-Site Request Forgery in Open WebUI Affects Image Upload Functionality
CVE-2026-45317
4.6MEDIUM
What is CVE-2026-45317?
Open WebUI, a self-hosted artificial intelligence platform, had a vulnerability in its image uploading functionality prior to version 0.9.3. The flaw allowed attackers to exploit cross-site request forgery (CSRF), enabling them to set malicious image URLs. When authenticated users viewed these images, they unknowingly sent GET requests to the attacker-controlled endpoints. This could lead to unauthorized actions being performed on behalf of the users, including potential cookie theft, denial of service, or other malicious activities. The issue has been resolved in version 0.9.3.
Affected Version(s)
open-webui < 0.9.3
