Skip to main content

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2025-64495

Severity Medium
Score 5.4/10

Summary

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions through 0.6.34, the functionality that inserts custom prompts into the chat window is vulnerable to DOM Cross-Site Scripting (XSS) when "Insert Prompt as Rich Text" is enabled, since the prompt body is assigned to the DOM sink ".innerHtml" without sanitization. Any user with permissions to create prompts can abuse this to plant a payload that could be triggered by other users if they run the corresponding "/" command to insert the prompt.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • REQUIRED
  • LOW
  • LOW
  • NONE

CWE-79 - Cross Site Scripting

Cross-Site Scripting, commonly referred to as XSS, is the most dominant class of vulnerabilities. It allows an attacker to inject malicious code into a pregnable web application and victimize its users. The exploitation of such a weakness can cause severe issues such as account takeover, and sensitive data exfiltration. Because of the prevalence of XSS vulnerabilities and their high rate of exploitation, it has remained in the OWASP top 10 vulnerabilities for years.

Advisory Timeline

  • Published