cvedb.io
CVE-2024-7990
HIGH · CVSS 8.4
EPSS exploitation probability: 0%
Published 2025-03-20T10:15:38.503 · Last modified 2026-06-17T08:21:37.647

Summary

A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution.

Affected products

openwebui — open_webui

Does this affect you?

Add your gear to cvedb and we'll alert you only when openwebui ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.