open-webui vulnerabilities
CVEs whose affected-version data names the open-webui package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
124 CVEsRSS
CVE-2026-54015Medium· 6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVE-2026-54016Medium· 4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVE-2026-54017High· 7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
CVE-2026-54018High· 7.7Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
CVE-2026-54019Medium· 6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-54021Medium· 6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
CVE-2026-54022Medium· 5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-56398High· 7.3Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
CVE-2026-45666Medium· 6.5Open WebUI has an Indirect Object Reference (IDOR) in user notes
Open WebUI has an Indirect Object Reference (IDOR) in user notes
CVE-2026-45385Medium· 4.3Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
CVE-2026-45365Medium· 5.4Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
CVE-2026-45396Medium· 5.4Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
CVE-2026-45401High· 8.5PoCOpen WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
CVE-2026-45301High· 8.1Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
CVE-2026-45402High· 8.1Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVE-2026-45315High· 8.7Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
CVE-2026-45667Medium· 6.5Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
CVE-2026-45316Low· 3.5PoCOpen WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
CVE-2026-45351Medium· 6.5Open WebUI Exposes System Prompt to Regular User [Non-Admin]
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
CVE-2026-45317Medium· 4.6Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVE-2026-45318Medium· 5.4Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
CVE-2026-45675High· 8.1Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVE-2026-45387Medium· 4.3Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
CVE-2026-45345Medium· 6.5Open WebUI missing authorization check at the model update function - models from other users can be updated
Open WebUI missing authorization check at the model update function - models from other users can be updated
CVE-2026-45349High· 7.1Open WebUI has Broken Access Control for Completions API
Open WebUI has Broken Access Control for Completions API
CVE-2026-45347Medium· 4.3Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
CVE-2026-45400High· 8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
CVE-2026-45399High· 7.1Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
CVE-2026-45299Medium· 5.4Open WebUI has Stored Cross-Site Scripting In Profile Picture
Open WebUI has Stored Cross-Site Scripting In Profile Picture
CVE-2026-45397Medium· 5.3PoCOpen WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure