Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
References
Link | Resource |
---|---|
https://korelogic.com/Resources/Advisories/KL-001-2024-005.txt | Exploit Third Party Advisory |
http://seclists.org/fulldisclosure/2024/Aug/3 | |
http://www.openwall.com/lists/oss-security/2024/08/08/6 |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-08-07 23:15
Updated : 2024-11-21 09:50
NVD link : CVE-2024-6706
Mitre link : CVE-2024-6706
CVE.ORG link : CVE-2024-6706
JSON object : View
Products Affected
openwebui
- open_webui
debian
- debian_linux
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')