CVE-2024-8017
CVSS 3.0 Score 9 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 79
Summary
CVE-2024-8017 is a cross-site scripting (XSS) vulnerability affecting open-webui versions 0.3.8 and below. The issue lies within the function responsible for generating HTML for tooltips. Attackers can exploit this flaw to execute malicious scripts, gaining the ability to perform actions on behalf of the victim, including stealing chat history, deleting chats, and potentially escalating their own account to an admin level if the victim holds administrative privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.