High severity8.9NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-7044
CVE-2024-7044
Description
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-webuiPyPI | <= 0.3.8 | — |
Affected products
3cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
3- huntr.com/bounties/c25a885c-d6e2-4169-9ee8-4d33bcbb5ef6nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-j274-m559-cj4jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-7044ghsaADVISORY
News mentions
0No linked articles in our index yet.