Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

open-webui — Vulnerabilities & Security Advisories 138

Browse all 138 CVE security advisories affecting open-webui. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Open-webui serves as a self-hosted, feature-rich interface for interacting with large language models, primarily enabling users to deploy and manage AI applications locally or within private networks. Its architecture, which bridges web clients with backend model services, has historically exposed it to critical vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and improper access control issues. With forty recorded CVEs, the software frequently suffers from insecure direct object references and authentication bypasses, often stemming from complex integration layers between the UI and underlying model APIs. Recent incidents highlight risks related to unvalidated file uploads and session management flaws, allowing attackers to escalate privileges or execute arbitrary commands. These recurring security gaps underscore the necessity for rigorous input validation and strict permission controls when deploying open-webui in production environments, particularly given its role in handling sensitive data interactions.

Top products by open-webui: open-webui open-webui/open-webui
CVE IDTitleCVSSSeverityPublished
CVE-2026-59714 Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) — open-webuiCWE-862 7.1 High2026-08-13
CVE-2026-70494 Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder — open-webuiCWE-862 8.1 High2026-08-04
CVE-2026-70493 Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically — open-webuiCWE-1333 6.5 Medium2026-08-04
CVE-2026-70492 Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages — open-webuiCWE-79 8.7 High2026-08-04
CVE-2026-70491 Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints — open-webuiCWE-200 6.5 Medium2026-08-04
CVE-2026-70490 Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check — open-webuiCWE-863 6.3 Medium2026-08-04
CVE-2026-70489 Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing — open-webuiCWE-400 6.5 Medium2026-08-04
CVE-2026-54020 Open WebUI: DNS Rebinding SSRF Bypass — open-webuiCWE-367 6.3 Medium2026-08-04
CVE-2026-70488 Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup — open-webuiCWE-639 4.3 Medium2026-08-04
CVE-2026-70487 Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata — open-webuiCWE-862 5.3 Medium2026-08-04
CVE-2026-70486 Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin — open-webuiCWE-79 8.2 High2026-08-04
CVE-2026-70485 Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs — open-webuiCWE-918 7.1 High2026-08-04
CVE-2026-70484 Open WebUI: Users denied the image-generation permission can still generate images via chat completions — open-webuiCWE-862 4.3 Medium2026-08-04
CVE-2026-70483 Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint — open-webuiCWE-862 3.1 Low2026-08-04
CVE-2026-70482 Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client — open-webuiCWE-287 8.1 High2026-08-04
CVE-2026-70481 Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages — open-webuiCWE-284 5.4 Medium2026-08-04
CVE-2026-70480 Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering — open-webuiCWE-918 4.1 Medium2026-08-04
CVE-2026-70479 Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader — open-webuiCWE-918 7.7 High2026-08-04
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation — open-webuiCWE-613 8.3 High2026-07-15
CVE-2026-56398 Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI — open-webuiCWE-20 7.3 High2026-07-15
CVE-2026-59221 open-webui terminal proxy path traversal guard bypass via 9x encoded traversal — open-webuiCWE-22 7.7 High2026-07-09
CVE-2026-59225 Open WebUI: Arena task endpoints can bypass underlying model access controls — open-webuiCWE-862 5.4 Medium2026-07-09
CVE-2026-59224 Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) — open-webuiCWE-287 8.0 High2026-07-09
CVE-2026-59212 Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete — open-webuiCWE-863 5.4 Medium2026-07-09
CVE-2026-59223 Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching — open-webuiCWE-693 4.3 Medium2026-07-09
CVE-2026-59222 Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials — open-webuiCWE-200--2026-07-09
CVE-2026-59215 Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding — open-webuiCWE-639 3.1 Low2026-07-09
CVE-2026-59213 Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) — open-webuiCWE-524 3.5 Low2026-07-09
CVE-2026-59217 Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) — open-webuiCWE-862 4.3 Medium2026-07-09
CVE-2026-59216 Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id — open-webuiCWE-94 7.7 High2026-07-09

This page lists every published CVE security advisory associated with open-webui. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.