open-webui vulnerabilities
CVEs whose affected-version data names the open-webui package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
124 CVEsRSS
CVE-2026-59714High· 7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM ch…
CVE-2026-59223Medium· 4.3Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-59212Medium· 5.4Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59225Medium· 5.4Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59221High· 7.7open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-59214High· 7.3Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-59218Medium· 5.3Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-59226Low· 3.1Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59220Medium· 6.5Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVE-2026-59227Medium· 4.3Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59715Low· 3.1Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVE-2026-59219High· 7.1Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVE-2026-59217Medium· 4.3Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59213Low· 3.5Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVE-2026-59222MediumOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2025-46571MediumOpen WebUI allows limited stored XSS vila uploaded html file
Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46719HighOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
CVE-2026-26192High· 7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26193High· 7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-34225Medium· 4.3Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-54006Medium· 4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
CVE-2026-54007HighOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-54008High· 8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
CVE-2026-54009Medium· 6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54013High· 7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-54014Medium· 4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}