{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/pyodide/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-59214"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open WebUI \u003c 0.10.0"],"_cs_severities":["high"],"_cs_tags":["xss","rce","pyodide","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Open WebUI"],"content_html":"\u003cp\u003eA high-severity vulnerability, CVE-2026-59214, affects Open WebUI versions prior to 0.10.0, enabling stored web worker Cross-Site Scripting (XSS) via Pyodide. This flaw allows a low-privileged user to inject malicious Python code into a chat message. When a victim, specifically an administrator or a user with \u003ccode\u003eworkspace.functions\u003c/code\u003e or \u003ccode\u003eworkspace.tools\u003c/code\u003e permissions, views the chat and clicks \u0026quot;Run\u0026quot;, the embedded Python code executes authenticated same-origin requests. This client-side execution can then be chained to create a server-side Function or Tool with arbitrary Python commands, leading to remote code execution (RCE) on the Open WebUI server. The vulnerability was published by GitHub Security Advisory (GHSA) on July 24, 2026.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA low-privileged attacker crafts a malicious Python payload using Pyodide's \u003ccode\u003epyodide.http.pyfetch\u003c/code\u003e or the \u003ccode\u003ejs\u003c/code\u003e module. The payload is designed to send an authenticated POST request to the \u003ccode\u003e/api/v1/functions/create\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe POST request body includes JSON data defining a new Function/Tool, whose \u003ccode\u003econtent\u003c/code\u003e field contains arbitrary Python commands for server-side execution, such as \u003ccode\u003eimport os; os.system('\u0026lt;attacker command\u0026gt;')\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker stores this malicious payload within an Open WebUI chat message.\u003c/li\u003e\n\u003cli\u003eThe attacker shares this chat message with a victim, who possesses elevated privileges (e.g., administrator or \u003ccode\u003eworkspace.functions\u003c/code\u003e/\u003ccode\u003eworkspace.tools\u003c/code\u003e permissions).\u003c/li\u003e\n\u003cli\u003eThe victim accesses the shared chat message containing the malicious Python payload.\u003c/li\u003e\n\u003cli\u003eThe victim clicks the \u0026quot;Run\u0026quot; button associated with the payload, triggering its execution within the client-side Pyodide web worker.\u003c/li\u003e\n\u003cli\u003eThe executed Pyodide payload leverages the victim's session cookie to send the crafted authenticated \u003ccode\u003e/api/v1/functions/create\u003c/code\u003e request to the Open WebUI server.\u003c/li\u003e\n\u003cli\u003eThe server processes the request, creating a new Function/Tool with the attacker's arbitrary Python code, leading to immediate remote code execution on the Open WebUI server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-59214 allows a low-privileged attacker to achieve remote code execution on the Open WebUI server. This impact is contingent on the victim being an administrator or a user holding \u003ccode\u003eworkspace.functions\u003c/code\u003e or \u003ccode\u003eworkspace.tools\u003c/code\u003e permissions. The attacker can then execute arbitrary system commands on the server, potentially leading to full system compromise, data exfiltration, or further lateral movement within the compromised environment. Even without RCE, the executed code can issue any authenticated request as the victim, enabling unauthorized actions or data access within the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the patch by upgrading Open WebUI to version 0.10.0 or later to address CVE-2026-59214, ensuring Pyodide runs in a sandboxed iframe.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, disable Pyodide code execution or configure the Code Execution / Code Interpreter engine to use a server-side option as a workaround.\u003c/li\u003e\n\u003cli\u003eImplement robust logging and monitoring for suspicious \u003ccode\u003ePOST\u003c/code\u003e requests targeting the \u003ccode\u003e/api/v1/functions/create\u003c/code\u003e endpoint on your Open WebUI instance, specifically looking for \u003ccode\u003econtent\u003c/code\u003e parameters within the request body that contain \u003ccode\u003eos.system\u003c/code\u003e or other indicators of arbitrary command execution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T16:57:17Z","date_published":"2026-07-24T16:57:17Z","id":"https://feed.craftedsignal.io/briefs/2026-07-open-webui-rce/","summary":"A stored web worker XSS vulnerability, CVE-2026-59214, in Open WebUI versions prior to 0.10.0 allows a low-privileged user to inject malicious Python code into chat messages that, when executed by an administrator or privileged user via a 'Run' click, triggers authenticated same-origin requests to create server-side functions with arbitrary commands, leading to remote code execution on the Open WebUI server.","title":"Open WebUI: Stored Web Worker XSS via Pyodide Leading to Server-Side RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-open-webui-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Pyodide","version":"https://jsonfeed.org/version/1.1"}