Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-45106Medium· 4.6Weblate: Stored HTML injection in editor search preview
Weblate: Stored HTML injection in editor search preview
CVE-2026-44716High· 7.5Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
Synapse CPU starvation (Denial of Service)
CVE-2026-45076MediumSynapse pagination Denial of Service
Synapse pagination Denial of Service
CVE-2026-44513High· 8.8Diffusers is the a library for pretrained diffusion models
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…
CVE-2026-45339Medium· 6.5Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
CVE-2026-56398High· 7.3Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
CVE-2026-44968Medium· 6.3dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
CVE-2026-45666Medium· 6.5Open WebUI has an Indirect Object Reference (IDOR) in user notes
Open WebUI has an Indirect Object Reference (IDOR) in user notes
CVE-2026-45385Medium· 4.3Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
CVE-2026-45306Medium· 6.5pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
CVE-2026-45365Medium· 5.4Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
CVE-2026-45396Medium· 5.4Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
CVE-2026-45401High· 8.5PoCOpen WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
CVE-2026-45301High· 8.1Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
CVE-2026-45402High· 8.1Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVE-2026-45315High· 8.7Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
CVE-2026-45667Medium· 6.5Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
CVE-2026-45316Low· 3.5PoCOpen WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
CVE-2026-44970Low· 3.1dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction
CVE-2026-45351Medium· 6.5Open WebUI Exposes System Prompt to Regular User [Non-Admin]
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
CVE-2026-45317Medium· 4.6Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVE-2026-45318Medium· 5.4Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
CVE-2026-45675High· 8.1Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVE-2026-45387Medium· 4.3Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
CVE-2026-45345Medium· 6.5Open WebUI missing authorization check at the model update function - models from other users can be updated
Open WebUI missing authorization check at the model update function - models from other users can be updated
CVE-2026-45349High· 7.1Open WebUI has Broken Access Control for Completions API
Open WebUI has Broken Access Control for Completions API
CVE-2026-45348High· 8.7pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
CVE-2026-45347Medium· 4.3Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
CVE-2026-44722Medium· 6.2pyzipper has an encryption bypass for small files encrypted using it
pyzipper has an encryption bypass for small files encrypted using it