open-webui has 124 CVEs on record between 2024 and 2026. Disclosures have slowed: 21 in the last 90 days after 73 in the 90 before. The busiest recent month was May 2026 with 56. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (9) and CWE-79 (7).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 21 prev 73
Worst active — by depth score
CVE-2025-64495High· 8.7Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE60CVE-2026-45401High· 8.5Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)59CVE-2024-12537High· 7.5Open WebUI Uncontrolled Resource Consumption vulnerability53CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed49CVE-2026-54011High· 8.7Open WebUI: Stored XSS in Mermaid Markdown Preview48
open-webui vulnerabilities
CVEs affecting open-webui, newest first. Open any entry for full detail, references, and exploit status.
124 CVEsRSS
CVE-2026-45386Medium· 4.3Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
CVE-2026-45303High· 7.7Open WebUI has stored XSS via the HTML renedering view
Open WebUI has stored XSS via the HTML renedering view
CVE-2026-45331High· 8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
CVE-2026-45350High· 7.1Open WebUI's chat completion API allows tool restrictions to be bypassed
Open WebUI's chat completion API allows tool restrictions to be bypassed
CVE-2026-45398High· 7.5Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVE-2026-45314Medium· 6.1Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
CVE-2026-45671High· 8.0Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVE-2026-45338High· 7.7Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
CVE-2026-56400High· 8.3Open WebUI has a CORS misconfiguration and session validation issue
Open WebUI has a CORS misconfiguration and session validation issue
CVE-2026-44569High· 7.1Open WebUI's Insecure Message Access Breaks Authorization
Open WebUI's Insecure Message Access Breaks Authorization
CVE-2026-44571Medium· 6.5Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVE-2026-44565High· 8.1Open WebUI Arbitrary File Write, Delete via Path Traversal
Open WebUI Arbitrary File Write, Delete via Path Traversal
CVE-2026-44570High· 8.3Open WebUI has inconsistent authorization controls within memories API
Open WebUI has inconsistent authorization controls within memories API
CVE-2026-44564Medium· 5.4Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
CVE-2026-44563Medium· 5.4Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVE-2026-44562Medium· 6.5Open WebUI's Model Import Overwrites Any Model Without Ownership Check
Open WebUI's Model Import Overwrites Any Model Without Ownership Check
CVE-2026-44549High· 7.3Open WebUI has stored XSS in Excel file preview
Open WebUI has stored XSS in Excel file preview
CVE-2026-44550Medium· 5.0Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVE-2026-44556High· 7.1Open WebUI's responses passthrough endpoint lacks access control authorization
Open WebUI's responses passthrough endpoint lacks access control authorization
CVE-2026-44561Medium· 5.4Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVE-2026-44560Medium· 6.5Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVE-2026-44721High· 7.3open-webui Vulnerable to Stored XSS via Model Description
open-webui Vulnerable to Stored XSS via Model Description
CVE-2026-44568Medium· 4.8Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
CVE-2026-44559Medium· 4.3Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
CVE-2026-44555High· 7.6Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
CVE-2026-44566High· 7.3Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-44558Medium· 5.4Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
CVE-2026-44554High· 8.1Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVE-2026-44557Medium· 4.3Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection