open-webui vulnerabilities
CVEs whose affected-version data names the open-webui package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
124 CVEsRSS
CVE-2026-44567High· 7.3Open WebUI has Improper Authorization Control
Open WebUI has Improper Authorization Control
CVE-2026-44553High· 8.1Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVE-2026-44552High· 8.7Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVE-2026-34222High· 7.7Open WebUI has Broken Access Control in Tool Valves
Open WebUI has Broken Access Control in Tool Valves
CVE-2026-29071Low· 3.1Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories
CVE-2026-28786Medium· 4.3Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`
CVE-2026-28788High· 7.1Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
CVE-2026-29070Medium· 5.4Open WebUI has unauthorized deletion of knowledge files
Open WebUI has unauthorized deletion of knowledge files
CVE-2025-63681Lowopen-webui is Vulnerable to Incorrect Access Control
open-webui is Vulnerable to Incorrect Access Control
CVE-2025-65958High· 8.5Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2025-64495High· 8.7PoCOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2025-64496High· 7.3Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2024-7959High· 7.7Open WebUI has SSRF in /openai/models
Open WebUI has SSRF in /openai/models
CVE-2024-7036High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7039High· 8.3Open WebUI Allows Admin Deletion via API Endpoint
Open WebUI Allows Admin Deletion via API Endpoint
CVE-2024-7035Medium· 6.9Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-7043High· 8.1Open WebUI Allows Arbitrary File Reading and Deletion
Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7044Medium· 6.8Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2024-7046Medium· 4.3Open WebUI Allows Viewing of Admin Details
Open WebUI Allows Viewing of Admin Details
CVE-2024-7990High· 8.4Open WebUI stored cross-site scripting (XSS) vulnerability
Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2024-12534High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-8060High· 8.1Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
CVE-2024-7034Medium· 6.5Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
CVE-2024-12537High· 7.5PoCOpen WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7045Medium· 4.3Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2024-8053High· 7.5Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
CVE-2024-7806High· 8.0Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2024-7983High· 7.5Open WebUI denial of service through endpoint for converting markdown
Open WebUI denial of service through endpoint for converting markdown
CVE-2024-7053High· 7.6Open WebUI Vulnerable to a Session Fixation Attack
Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7033Medium· 6.5Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint