The developers behind Open WebUI, an open-source and self-hosted AI interface framework, have issued a security advisory disclosing a high-severity vulnerability (CVE-2025-64495, CVSS 8.7) affecting versions up to 0.6.34. The flaw resides in the platformβs prompt-handling functionality when the βInsert Prompt as Rich Textβ feature is enabled, allowing attackers to achieve stored DOM-based cross-site scripting (XSS) that can escalate to account takeover (ATO) or even remote code execution (RCE) on the host system.
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysAccording to the project maintainers, βThe functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when βInsert Prompt as Rich Textβ is enabled, since the prompt body is assigned to the DOM sink .innerHTML without sanitisation.β
This means that any user with permission to create prompts can inject malicious HTML or JavaScript code into the platform, which will execute whenever another user interacts with the compromised prompt.
The vulnerability stems from a code fragment in open-webui/src/lib/components/common/RichTextInput.svelte at line 348, where user-supplied HTML is directly rendered in the browser.
βUser-controlled HTML from the prompt body is assigned to tempDiv.innerHTML without (meaningful) sanitisation,β the advisory explains, adding that the Markdown parser used (marked.parse) βdoes not sanitise the content, as stated in their README.β
Researchers demonstrated a proof-of-concept (PoC) exploit where an attacker could craft a malicious prompt and trigger it using the /poc command in the chat interface. Upon execution, the injected payload would run in the victimβs browser context, potentially exfiltrating session tokens or performing unauthorized actions.
While this flaw is serious for any user, the risk becomes catastrophic if an administrator account is affected. The advisory warns that:
βSince admins can naturally run arbitrary Python code on the server via the βFunctionsβ feature, this XSS could be used to force any admin that triggers it to run one such function with Python code of the attackerβs choosing.β
By exploiting the XSS to impersonate legitimate admin requests, attackers can create and execute malicious server-side Python functions. One of the provided PoC payloads used the following technique:
If successfully triggered, the payload can open a reverse shell connection from the Open WebUI host, granting the attacker full command-line control.
The Open WebUI project has addressed this issue in version 0.6.35, which introduces proper HTML sanitization.
Users and administrators are strongly advised to upgrade immediately and verify that βInsert Prompt as Rich Textβ remains disabled unless strictly required. Enabling Content Security Policy (CSP) and sandboxing mechanisms is also recommended to further reduce exposure.
Related Posts:
- AI Interface Hijacked: Open WebUI Exploited for Cryptominers and Stealthy AI Malware
- Microsoft Edge Achieves Sub-300ms FCP: Browser UI Now Loads Instantly
- CVE-2022-23494: XSS vulnerability affects the TinyMCE rich text editor
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!