<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:52:28.125921+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07203</id>
    <title>bdu:2026-07203</title>
    <updated>2026-10-03T01:52:28.206237+00:00</updated>
    <content>bdu:2026-07203</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07203"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319337</id>
    <title>EUVD-2026-319337</title>
    <updated>2026-10-03T01:52:28.206273+00:00</updated>
    <content>EUVD-2026-319337</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45314</id>
    <title>fkie_cve-2026-45314</title>
    <updated>2026-10-03T01:52:28.206287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the channel webhook create/update flow accepts arbitrary profile_image_url values, including data:image/svg+xml;base64,... payloads. The profile image endpoint then decodes and serves this SVG as image/svg+xml without sanitization, allowing attacker-controlled script handlers (for example onload) to execute when the profile-image URL is opened in the browser. This vulnerability is fixed in 0.9.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3856-3vxq-m6fc</id>
    <title>GHSA-3856-3vxq-m6fc — Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image</title>
    <updated>2026-10-03T01:52:28.206317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>As part of our research on improving our [AI pentest](https://www.aikido.dev/attack/aipentest), we have uncovered the following issue in Open WebUI. We've manually verified and tided up the report, but you can also find the original agent finding at the bottom of this report.</p>
<p>### Summary</p>
<p>The channel webhook create/update flow accepts arbitrary `profile_image_url` values, including `data:image/svg+xml;base64,...` payloads. The profile image endpoint then decodes and serves this SVG as `image/svg+xml` without sanitization, allowing attacker-controlled script handlers (for example onload) to execute when the profile-image URL is opened in the browser.</p>
<p>### Details</p>
<p>The server accepts `data:image/svg+xml;base64,...` values for `profile_image_url` when creating or updating a webhook. Later, `GET /api/v1/channels/webhooks/{webhook_id}/profile/image` detects `data:image`, base64-decodes it, derives the media type from the header (e.g., `image/svg+xml`), and returns a `StreamingResponse` with `Content-Disposition: inline` and `media_type` set to `image/svg+xml`. There is no sanitization or transformation. When this URL is opened in a browser, SVG event handlers such as onload execute in the application origin, resulting in stored XSS.</p>
<p>### PoC</p>
<p>1. Set up a new instance of Open WebUI and log in as admin
2. In the Admin Panel, enable *Channels (Beta)* and click Save
3. Create a low-privilege user in the Users tab
4. As the attacker, use the low-privilege user to run the following sc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3856-3vxq-m6fc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2694</id>
    <title>PYSEC-2026-2694 — Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image</title>
    <updated>2026-10-03T01:52:28.206367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>As part of our research on improving our [AI pentest](https://www.aikido.dev/attack/aipentest), we have uncovered the following issue in Open WebUI. We've manually verified and tided up the report, but you can also find the original agent finding at the bottom of this report.</p>
<p>### Summary</p>
<p>The channel webhook create/update flow accepts arbitrary `profile_image_url` values, including `data:image/svg+xml;base64,...` payloads. The profile image endpoint then decodes and serves this SVG as `image/svg+xml` without sanitization, allowing attacker-controlled script handlers (for example onload) to execute when the profile-image URL is opened in the browser.</p>
<p>### Details</p>
<p>The server accepts `data:image/svg+xml;base64,...` values for `profile_image_url` when creating or updating a webhook. Later, `GET /api/v1/channels/webhooks/{webhook_id}/profile/image` detects `data:image`, base64-decodes it, derives the media type from the header (e.g., `image/svg+xml`), and returns a `StreamingResponse` with `Content-Disposition: inline` and `media_type` set to `image/svg+xml`. There is no sanitization or transformation. When this URL is opened in a browser, SVG event handlers such as onload execute in the application origin, resulting in stored XSS.</p>
<p>### PoC</p>
<p>1. Set up a new instance of Open WebUI and log in as admin
2. In the Admin Panel, enable *Channels (Beta)* and click Save
3. Create a low-privilege user in the Users tab
4. As the attacker, use the low-privilege user to run the following sc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2694"/>
  </entry>
</feed>
