Open WebUI: Stored web worker XSS via Pyodide
A shared chat payload can act as the victim and let an admin create server-side code, leading to full remote code execution.

2 CRIT · 6 HIGH · 2 MED · 2 INFO · THREAT RED · 12 items · Generated in 271s
A shared chat payload can act as the victim and let an admin create server-side code, leading to full remote code execution.
Authenticated attackers can write files outside the skills directory and may achieve code execution on vulnerable deployments.
Unauthenticated attackers can invoke MCP tools and reach connected services by bypassing LiteLLM key checks.
An authorized remote user can send one crafted request to crash the vLLM server and stop inference.
Missing auth checks let a member run another user's MCP workflow with the owner's credentials and access its integration data.
Bypassing the proxy path guard can send privileged terminal requests to unintended paths using configured credentials.
If startup init fails, policy checks are skipped and restricted AWS operations can run without enforcement until restart.
Privileged users could read local files through test_connection, exposing secrets or config from the LiteLLM host.
This is a product/research announcement about AI-assisted vuln research, not a disclosed vulnerability or active threat.
Research result weakens test crypto schemes and reduced-round AES, but it is not a direct production vulnerability by itself.
Sandbox escapes can let agents reach unintended systems or data, so isolation and logging controls remain essential.
Shows AI can exploit real zero-days to break isolation and reach external networks, raising containment and test environment risks.