VulnSea

open-webui vulnerabilities

CVEs whose affected-version data names the open-webui package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

124 CVEsRSS

CVE-2026-59714High· 7.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM ch…

Twilightopen-webui · open-webuiEPSS 0.34%via NVD
CVE-2026-59223Medium· 4.3
2mo ago

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Sunlitopen-webui · open-webuiEPSS 0.38%via GHSA
CVE-2026-59224High· 8.0
2mo ago

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Twilightopen-webui · open-webuiEPSS 0.39%via GHSA
CVE-2026-59212Medium· 5.4
2mo ago

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59225Medium· 5.4
2mo ago

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

Sunlitopen-webui · open-webuiEPSS 0.21%via GHSA
CVE-2026-59221High· 7.7
2mo ago

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

Twilightopen-webui · open-webuiEPSS 0.48%via GHSA
CVE-2026-59214High· 7.3
2mo ago

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

Twilightopen-webui · open-webuiEPSS 0.29%via GHSA
CVE-2026-59218Medium· 5.3
2mo ago

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

Sunlitopen-webui · open-webuiEPSS 0.41%via GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-59220Medium· 6.5
2mo ago

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Sunlitopen-webui · open-webuiEPSS 0.57%via GHSA
CVE-2026-59227Medium· 4.3
2mo ago

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Sunlitopen-webui · open-webuiEPSS 0.26%via GHSA
CVE-2026-59715Low· 3.1
2mo ago

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Sunlitopen-webui · open-webuiEPSS 0.22%via GHSA
CVE-2026-59219High· 7.1
2mo ago

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Twilightopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-59217Medium· 4.3
2mo ago

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59213Low· 3.5
2mo ago

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-59222Medium
2mo ago

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Sunlitopen-webui · open-webuiEPSS 0.32%via GHSA
CVE-2025-46571Medium
2mo ago

Open WebUI allows limited stored XSS vila uploaded html file

Open WebUI allows limited stored XSS vila uploaded html file

Sunlitopen-webui · open-webuiEPSS 0.35%via GHSA
CVE-2025-46719High
2mo ago

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions

Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions

Twilightopen-webui · open-webuiEPSS 0.54%via GHSA
CVE-2026-26192High· 7.3
2mo ago

Open WebUI vulnerable to Stored XSS via iFrame in citations model

Open WebUI vulnerable to Stored XSS via iFrame in citations model

Twilightopen-webui · open-webuiEPSS 0.20%via GHSA
CVE-2026-26193High· 7.3
2mo ago

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

Twilightopen-webui · open-webuiEPSS 0.20%via GHSA
CVE-2026-34225Medium· 4.3
2mo ago

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality

Sunlitopen-webui · open-webuiEPSS 0.29%via GHSA
CVE-2026-54006Medium· 4.3
3mo ago

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-54007High
3mo ago

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

Twilightopen-webui · open-webuiEPSS 0.23%via GHSA
CVE-2026-54008High· 8.5
3mo ago

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

Twilightopen-webui · open-webuiEPSS 0.33%via GHSA
CVE-2026-54009Medium· 6.5
3mo ago

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

Sunlitopen-webui · open-webuiEPSS 0.38%via GHSA
CVE-2026-54010High· 8.3
3mo ago

Open WebUI: Forged chat-file link allows cross-user file read and deletion

Open WebUI: Forged chat-file link allows cross-user file read and deletion

Twilightopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-54011High· 8.7
3mo ago

Open WebUI: Stored XSS in Mermaid Markdown Preview

Open WebUI: Stored XSS in Mermaid Markdown Preview

Twilightopen-webui · open-webuiEPSS 0.34%via GHSA
CVE-2026-54012High· 7.1
3mo ago

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Twilightopen-webui · open-webuiEPSS 0.33%via GHSA
CVE-2026-54013High· 7.6
3mo ago

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

Twilightopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-54014Medium· 4.3
3mo ago

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

Sunlitopen-webui · open-webuiEPSS 0.36%via GHSA
open-webui vulnerabilities (CVEs) · VulnSea