{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T13:18:30.488","vulnerabilities":[{"cve":{"id":"CVE-2024-8017","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:38.763","lastModified":"2026-06-17T08:21:41.773","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin."},{"lang":"es","value":"Existe una vulnerabilidad XSS en las versiones de open-webui/open-webui anteriores a la 0.3.8, específicamente en la función que genera el HTML para las descripciones emergentes. Esta vulnerabilidad permite a los atacantes realizar operaciones con los privilegios de la víctima, como robar el historial de chat, eliminar chats y escalar su propia cuenta a administrador si la víctima lo es."}],"affected":[{"source":"security@huntr.dev","affectedData":[{"vendor":"open-webui","product":"open-webui/open-webui","versions":[{"version":"unspecified","lessThanOrEqual":"latest","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":9.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-20T14:17:43.801749Z","id":"CVE-2024-8017","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*","versionEndIncluding":"0.3.8","matchCriteriaId":"B15E1DFB-EF7D-4820-B6A9-2D5CD943C9A1"}]}]}],"references":[{"url":"https://huntr.com/bounties/ef06c7c8-1cb2-42a7-a6e6-17b2e1c744f7","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}