VulnSea

open_webui vulnerabilities

CVEs whose affected-version data names the open_webui package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

37 CVEsRSS

CVE-2026-70486High· 8.2
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…

Twilightopenwebui · open_webuiEPSS 0.31%via NVD
CVE-2026-70488Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids su…

Sunlitopenwebui · open_webuiEPSS 0.21%via NVD
CVE-2026-70487Medium· 5.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read a…

Sunlitopenwebui · open_webuiEPSS 0.25%via NVD
CVE-2026-54020Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…

Sunlitopenwebui · open_webuiEPSS 0.21%via NVD
CVE-2026-70479High· 7.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…

Twilightopenwebui · open_webuiEPSS 0.27%via NVD
CVE-2026-59215Low· 3.1
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference…

Sunlitopenwebui · open_webuiEPSS 0.32%via NVD
CVE-2026-59216High· 7.7
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…

Twilightopenwebui · open_webuiEPSS 0.31%via NVD
open_webui vulnerabilities (CVEs) — page 2 · VulnSea