<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T11:07:01.876991+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-54013</id>
    <title>CVE-2026-54013 — Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI</title>
    <updated>2026-10-06T11:07:01.908153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> open-webui</p>
<p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. The ModelMeta class has no validate_profile_image_url field validator, and the model image serving endpoint has no MIME allowlist or nosniff header. Any authenticated user with workspace.models permission (enabled by default) can store a data:image/svg+xml;base64,... payload in a model's profile image and achieve full account takeover of anyone who navigates to the image URL. This vulnerability is fixed in 0.9.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-54013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v2qm-5wxj-qhj7</id>
    <title>GHSA-v2qm-5wxj-qhj7 — Open WebUI: Stored XSS to Account Takeover via Model Profile Images</title>
    <updated>2026-10-06T11:07:01.908214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p># Stored XSS to Account Takeover via Model Profile Images in Open WebUI</p>
<p>**Affected:** Open WebUI &lt;= 0.9.5
**Bypass of:** GHSA-3wgj-c2hg-vm6q, GHSA-3856-3vxq-m6fc</p>
<p>---</p>
<p>## TL;DR</p>
<p>Open WebUI patched SVG XSS in user profile images and webhook profile images  but forgot to apply the same fix to **model** profile images. The `ModelMeta` class has no `validate_profile_image_url` field validator, and the model image serving endpoint has no MIME allowlist or `nosniff` header. Any authenticated user with `workspace.models` permission (enabled by default) can store a `data:image/svg+xml;base64,...` payload in a model's profile image and achieve full account takeover of anyone who navigates to the image URL.</p>
<p>---</p>
<p>## Past of the issue</p>
<p>In early 2025, two security advisories landed for Open WebUI:</p>
<p>- **GHSA-3wgj-c2hg-vm6q**  SVG XSS via user profile images
- **GHSA-3856-3vxq-m6fc**  SVG XSS via webhook profile images</p>
<p>The patches were clean. A `validate_profile_image_url` function was introduced in `backend/open_webui/utils/validate.py`  a compiled regex that restricts `data:` URIs to safe raster formats (`image/png`, `image/jpeg`, `image/gif`, `image/webp`), explicitly excluding `image/svg+xml` because SVG can carry embedded `&lt;script&gt;` tags. On the output side, `users.py` added a MIME allowlist check and `X-Content-Type-Options: nosniff`.</p>
<p>The fix was applied to `UserUpdateForm`, `UpdateProfileForm`, and later to `ChannelWebhookForm`. Three models patched. Case closed.</p>
<p>Except there w…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v2qm-5wxj-qhj7"/>
  </entry>
</feed>
