CVE-2024-6706: Open WebUI Stored Cross-Site Scripting
Published Aug 7, 2024
·Updated
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
Affected Software
3 affected components
pip/open-webui<=0.1.105
All of the following
openwebui Open WebUI=0.1.105
Debian Debian Linux=12.0
Event History
Aug 7, 2024
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
DescriptionWeakness
Aug 8, 2024
Advisory Published
via GitHub·12:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-6706?
CVE-2024-6706 has been classified as a high severity vulnerability due to the potential for arbitrary JavaScript execution.
2
How do I fix CVE-2024-6706?
To mitigate CVE-2024-6706, it's advised to update the open-webui package to a version higher than 0.1.105.
3
What software is affected by CVE-2024-6706?
CVE-2024-6706 affects the open-webui package version 0.1.105 and lower.
4
Can CVE-2024-6706 be exploited remotely?
Yes, CVE-2024-6706 can be exploited remotely by attackers who craft a malicious prompt.
5
Is CVE-2024-6706 a known issue in Debian Linux?
CVE-2024-6706 is associated with the open-webui package and its version can affect systems running Debian Linux 12.0.