CVE-2026-87997Medium· 4.3▾ TwilightPoC availableOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Exploit / PoC code exists
Last analysed / modified upstream
0.2% → 0.2%
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id into a new chat without applying the folder write-access check used by the dedicated chat routes. An authenticated user who knew a shared folder identifier could inject an attacker-controlled chat into a folder where the user had read-only or no write access, causing the entry to appear to authorized folder readers. This issue is fixed in version 0.11.1.
open_webui >= 0.10.0, < 0.11.1Upgrade past the affected range:
open_webui 0.11.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87994Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87016High· 8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87011High· 7.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-88001Medium· 5.0Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-88000Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87013Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform