Gbhackers Critical Open WebUI Vulnerability Enables Remote Code Execution
Article Content
- •Open WebUI has a critical unpatched XSS vulnerability allowing RCE and account hijacking.
- •The flaw is exploited via profile image uploads, affecting all users of the platform.
- •No patch is currently available, increasing the urgency for users to take preventive measures.
A critical, unpatched vulnerability in Open WebUI allows attackers to exploit a stored Cross-Site Scripting (XSS) flaw through profile image uploads. This vulnerability enables 1-click Remote Code Execution (RCE), full account hijacking, and access to sensitive chat histories. Discovered by security researcher Metin Yunus Kandemir, the flaw poses a significant risk to users of the platform. Currently, there is no patch available, leaving systems vulnerable to exploitation. The flaw affects all users who utilize the profile image upload feature, potentially compromising AI workspaces and sensitive information. Security researchers have publicly disclosed the issue, emphasizing the urgency for users to secure their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…