Tagged “osv”
CVEs tagged osv, newest first.
5681 CVEsRSS
CVE-2026-45318Medium· 5.4Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
CVE-2026-45675High· 8.1Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVE-2026-45387Medium· 4.3Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
CVE-2026-45345Medium· 6.5Open WebUI missing authorization check at the model update function - models from other users can be updated
Open WebUI missing authorization check at the model update function - models from other users can be updated
CVE-2026-45349High· 7.1Open WebUI has Broken Access Control for Completions API
Open WebUI has Broken Access Control for Completions API
CVE-2026-45348High· 8.7pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
CVE-2026-45347Medium· 4.3Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
CVE-2026-44722Medium· 6.2pyzipper has an encryption bypass for small files encrypted using it
pyzipper has an encryption bypass for small files encrypted using it
CVE-2026-43977High· 7.5wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
CVE-2026-44899Medium· 4.7Mistune Image Directive CSS Injection Vulnerability
Mistune Image Directive CSS Injection Vulnerability
CVE-2026-43978High· 8.1wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
CVE-2026-45400High· 8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
CVE-2026-45399High· 7.1Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
CVE-2026-44969Low· 2.5dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
CVE-2026-45299Medium· 5.4Open WebUI has Stored Cross-Site Scripting In Profile Picture
Open WebUI has Stored Cross-Site Scripting In Profile Picture
CVE-2026-45397Medium· 5.3PoCOpen WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
CVE-2026-44898Medium· 6.1Mistune TOC Anchor Injection XSS
Mistune TOC Anchor Injection XSS
CVE-2026-45370High· 7.7python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
CVE-2026-44541Highethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
CVE-2026-45386Medium· 4.3Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
CVE-2026-45303High· 7.7Open WebUI has stored XSS via the HTML renedering view
Open WebUI has stored XSS via the HTML renedering view
CVE-2026-45331High· 8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
CVE-2026-45350High· 7.1Open WebUI's chat completion API allows tool restrictions to be bypassed
Open WebUI's chat completion API allows tool restrictions to be bypassed
CVE-2026-44919Medium· 4.3OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
CVE-2026-45398High· 7.5Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVE-2026-45314Medium· 6.1Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
CVE-2026-45671High· 8.0Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVE-2026-45338High· 7.7Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
CVE-2026-44885Medium· 5.5Portainer has a path traversal in backup archive extraction that allows arbitrary file write
Portainer has a path traversal in backup archive extraction that allows arbitrary file write