Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

open-webui — Vulnerabilities & Security Advisories 129

Browse all 129 CVE security advisories affecting open-webui. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Open-webui serves as a self-hosted, feature-rich interface for interacting with large language models, primarily enabling users to deploy and manage AI applications locally or within private networks. Its architecture, which bridges web clients with backend model services, has historically exposed it to critical vulnerabilities, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and improper access control issues. With forty recorded CVEs, the software frequently suffers from insecure direct object references and authentication bypasses, often stemming from complex integration layers between the UI and underlying model APIs. Recent incidents highlight risks related to unvalidated file uploads and session management flaws, allowing attackers to escalate privileges or execute arbitrary commands. These recurring security gaps underscore the necessity for rigorous input validation and strict permission controls when deploying open-webui in production environments, particularly given its role in handling sensitive data interactions.

Found 110 results / 129Clear Filters
Top products by open-webui: open-webui open-webui/open-webui
CVE IDTitleCVSSSeverityPublished
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation — open-webuiCWE-613 8.3 High2026-07-15
CVE-2026-56398 Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI — open-webuiCWE-20 7.3 High2026-07-15
CVE-2026-59221 open-webui terminal proxy path traversal guard bypass via 9x encoded traversal — open-webuiCWE-22 7.7 High2026-07-09
CVE-2026-59225 Open WebUI: Arena task endpoints can bypass underlying model access controls — open-webuiCWE-862 5.4 Medium2026-07-09
CVE-2026-59224 Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) — open-webuiCWE-287 8.0 High2026-07-09
CVE-2026-59212 Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete — open-webuiCWE-863 5.4 Medium2026-07-09
CVE-2026-59223 Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching — open-webuiCWE-693 4.3 Medium2026-07-09
CVE-2026-59222 Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials — open-webuiCWE-200--2026-07-09
CVE-2026-59215 Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding — open-webuiCWE-639 3.1 Low2026-07-09
CVE-2026-59213 Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) — open-webuiCWE-524 3.5 Low2026-07-09
CVE-2026-59217 Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) — open-webuiCWE-862 4.3 Medium2026-07-09
CVE-2026-59216 Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id — open-webuiCWE-94 7.7 High2026-07-09
CVE-2026-59219 Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout — open-webuiCWE-613 7.1 High2026-07-09
CVE-2026-59715 Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave) — open-webuiCWE-306 3.1 Low2026-07-09
CVE-2026-59220 Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config — open-webuiCWE-1333 6.5 Medium2026-07-09
CVE-2026-59226 Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation — open-webuiCWE-285 3.1 Low2026-07-09
CVE-2026-59227 Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission — open-webuiCWE-862 4.3 Medium2026-07-09
CVE-2026-59218 Open WebUI: Account enumeration via observable login timing discrepancy — open-webuiCWE-208 5.3 Medium2026-07-09
CVE-2026-59214 Open WebUI: Stored web worker XSS via Pyodide — open-webuiCWE-79 7.3 High2026-07-09
CVE-2026-56399 Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/web — open-webuiCWE-918 5.0 Medium2026-06-30
CVE-2026-54007 Open WebUI: Cross-origin postMessage confirmation bypass via action:submit — open-webuiCWE-346--2026-06-23
CVE-2026-54006 Open WebUI: Calendar event re-parenting allows writing events into another user's calendar — open-webuiCWE-639 4.3 Medium2026-06-23
CVE-2026-54008 Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` — open-webuiCWE-918 8.5 High2026-06-23
CVE-2026-54009 Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field — open-webuiCWE-639 6.5 Medium2026-06-23
CVE-2026-54010 Open WebUI: Forged chat-file link allows cross-user file read and deletion — open-webuiCWE-284 8.3 High2026-06-23
CVE-2026-54011 Open WebUI: Stored XSS in Mermaid Markdown Preview — open-webuiCWE-79 8.7 High2026-06-23
CVE-2026-54012 Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion — open-webuiCWE-284 7.1 High2026-06-23
CVE-2026-54013 Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI — open-webuiCWE-79 7.6 High2026-06-23
CVE-2026-54014 Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui — open-webuiCWE-22 4.3 Medium2026-06-23
CVE-2026-54015 Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion — open-webuiCWE-284 6.4 Medium2026-06-23

This page lists every published CVE security advisory associated with open-webui. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.