open-webui has 124 CVEs on record between 2024 and 2026. Disclosures have slowed: 21 in the last 90 days after 77 in the 90 before. The busiest recent month was May 2026 with 56. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (9) and CWE-79 (7).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 21 prev 77
Worst active — by depth score
CVE-2025-64495High· 8.7Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE60CVE-2026-45401High· 8.5Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)59CVE-2024-12537High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability53CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview48CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed48
open-webui vulnerabilities
CVEs affecting open-webui, newest first. Open any entry for full detail, references, and exploit status.
124 CVEsRSS
CVE-2026-59714High· 7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM ch…
CVE-2026-59223Medium· 4.3Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-59212Medium· 5.4Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59225Medium· 5.4Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59221High· 7.7open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-59214High· 7.3Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-59218Medium· 5.3Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-59226Low· 3.1Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59220Medium· 6.5Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVE-2026-59227Medium· 4.3Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59715Low· 3.1Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVE-2026-59219High· 7.1Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVE-2026-59217Medium· 4.3Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59213Low· 3.5Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVE-2026-59222MediumOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2025-46571MediumOpen WebUI allows limited stored XSS vila uploaded html file
Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46719HighOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
CVE-2026-26192High· 7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26193High· 7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-34225Medium· 4.3Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-54006Medium· 4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
CVE-2026-54007HighOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-54008High· 8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
CVE-2026-54009Medium· 6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54013High· 7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-54014Medium· 4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}