vciy

CVEs we hold for Open-webui

Records whose assigning authority named Open-webui as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchangeopen-webui
CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangeopen-webui
CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message historyopen-webui
CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsopen-webui
CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat treeopen-webui
CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchopen-webui
CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionopen-webui
CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsopen-webui
CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderopen-webui
CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originopen-webui
CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpointopen-webui
CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsopen-webui
CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopen-webui
CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authenticationopen-webui
CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesopen-webui
CVE-2026-87013Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycleopen-webui
CVE-2026-87012Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueopen-webui
CVE-2026-87011Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopen-webui
CVE-2026-70494Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolderopen-webui
CVE-2026-70493Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophicallyopen-webui
CVE-2026-70492Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messagesopen-webui
CVE-2026-70491Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpointsopen-webui
CVE-2026-70490Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role checkopen-webui
CVE-2026-70489Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsingopen-webui
CVE-2026-70488Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanupopen-webui
CVE-2026-70487Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadataopen-webui
CVE-2026-70486Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originopen-webui
CVE-2026-70485Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLsopen-webui
CVE-2026-70484Open WebUI: Users denied the image-generation permission can still generate images via chat completionsopen-webui
CVE-2026-70483Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpointopen-webui
CVE-2026-70482Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clientopen-webui
CVE-2026-70481Open WebUI: Any member with write access to a standard channel can edit or delete other members' messagesopen-webui
CVE-2026-70480Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart renderingopen-webui
CVE-2026-70479Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loaderopen-webui
CVE-2026-59715Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update…open-webui
CVE-2026-59714Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)open-webui
CVE-2026-59227Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permissionopen-webui
CVE-2026-59226Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocationopen-webui
CVE-2026-59225Open WebUI: Arena task endpoints can bypass underlying model access controlsopen-webui
CVE-2026-59224Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and…open-webui
CVE-2026-59223Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingopen-webui
CVE-2026-59222Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentialsopen-webui
CVE-2026-59221open-webui terminal proxy path traversal guard bypass via 9x encoded traversalopen-webui
CVE-2026-59220Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default configopen-webui
CVE-2026-59219Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logoutopen-webui
CVE-2026-59218Open WebUI: Account enumeration via observable login timing discrepancyopen-webui
CVE-2026-59217Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add…open-webui
CVE-2026-59216Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idopen-webui
CVE-2026-59215Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id bindingopen-webui
CVE-2026-59214Open WebUI: Stored web worker XSS via Pyodideopen-webui
CVE-2026-59213Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)open-webui
CVE-2026-59212Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/deleteopen-webui
CVE-2026-56400open-webui - Remote Code Execution via CORS Misconfiguration and Session Validationopen-webui
CVE-2026-56399Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/webopen-webui
CVE-2026-56398Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URIopen-webui
CVE-2026-54022Open WebUI: Any authenticated user can read other users' private notes via Socket.IOopen-webui
CVE-2026-54021Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameteropen-webui
CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypassopen-webui
CVE-2026-54019Open WebUI: RAG ACL Bypass in Milvus Multitenancy Modeopen-webui
CVE-2026-54018Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirectsopen-webui
CVE-2026-54017Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalopen-webui
CVE-2026-54016Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumerationopen-webui
CVE-2026-54015Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletionopen-webui
CVE-2026-54014Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webuiopen-webui
CVE-2026-54013Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUIopen-webui
CVE-2026-54012Open WebUI: Forged model meta.knowledge allows cross-user file read and deletionopen-webui
CVE-2026-54011Open WebUI: Stored XSS in Mermaid Markdown Previewopen-webui
CVE-2026-54010Open WebUI: Forged chat-file link allows cross-user file read and deletionopen-webui
CVE-2026-54009Open WebUI: Cross-user file disclosure via /api/chat/completions image_url fieldopen-webui
CVE-2026-54008Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`open-webui
CVE-2026-54007Open WebUI: Cross-origin postMessage confirmation bypass via action:submitopen-webui
CVE-2026-54006Open WebUI: Calendar event re-parenting allows writing events into another user's calendaropen-webui
CVE-2026-45675Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accountsopen-webui
CVE-2026-45672Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassedopen-webui
CVE-2026-45671Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletionopen-webui
CVE-2026-45667Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)open-webui
CVE-2026-45666Open WebUI: Indirect Object Reference (IDOR) in user notesopen-webui
CVE-2026-45665Open WebUI: Stored XSS in Banner Component via Improper Sanitization Orderopen-webui
CVE-2026-45402Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpointsopen-webui
CVE-2026-45401Open WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpointsopen-webui
CVE-2026-45400Open WebUI: Server-Side Request Forgery (SSRF) bypass in `validate_url`open-webui
CVE-2026-45399Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat…open-webui
CVE-2026-45398Open WebUI: IDOR - Retrieval API Bypasses Knowledge Base Access Controlsopen-webui
CVE-2026-45397Open WebUI: Unauthenticated RAG Configuration Disclosureopen-webui
CVE-2026-45396Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data…open-webui
CVE-2026-45395Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code…open-webui
CVE-2026-45387Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)open-webui
CVE-2026-45386Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpointopen-webui
CVE-2026-45385Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpointopen-webui
CVE-2026-45365Open WebUI: Authenticated users can bypass model access control via exposed query parameteropen-webui
CVE-2026-45351Open WebUI: Exposure of System Prompt to Regular User [Non-Admin]open-webui
CVE-2026-45350Open WebUI: Chat completion API allows tool restrictions to be bypassedopen-webui
CVE-2026-45349Open WebUI: Broken Access Control for Completions APIopen-webui
CVE-2026-45347Open WebUI: Blind server side request forgery (SSRF) via the PDF generate functionopen-webui
CVE-2026-45346Open WebUI: Stored Cross-Site Scripting in SVG Rendereropen-webui
CVE-2026-45345Open WebUI: Missing authorization check at the model update function - models from other users can be updatedopen-webui
CVE-2026-45339Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted…open-webui
CVE-2026-45338Open WebUI: SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)open-webui
CVE-2026-45331Open WebUI: Full SSRF Vulnerability in the RAG Web Search Featureopen-webui
CVE-2026-45318Open WebUI: Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)open-webui
CVE-2026-45317Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulationopen-webui
CVE-2026-45316Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)open-webui
CVE-2026-45315Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptionsopen-webui
CVE-2026-45314Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/imageopen-webui
CVE-2026-45303Open WebUI: Stored XSS via the HTML renedering viewopen-webui
CVE-2026-45301Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded…open-webui
CVE-2026-45299Open WebUI: Stored Cross-Site Scripting In Profile Pictureopen-webui
CVE-2026-44721Open WebUI: Stored XSS via Model Descriptionopen-webui
CVE-2026-44571Open WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read Permissionopen-webui
CVE-2026-44570Open WebUI: Inconsistent authorization controls within memories APIopen-webui
CVE-2026-44569Open WebUI: Insecure Message Access Breaks Authorizationopen-webui
CVE-2026-44568Open WebUI: Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Orderopen-webui
CVE-2026-44567Open WebUI: Open WebUI Improper Authorization Controlopen-webui
CVE-2026-44566Open WebUI: Arbitrary File Upload and Path Traversalopen-webui
CVE-2026-44565Open WebUI: Open WebUI Arbitrary File Write, Delete via Path Traversalopen-webui
CVE-2026-44564Open WebUI: Read-Only Users Can Modify Collaborative Documents via Socket.IOopen-webui
CVE-2026-44563Open WebUI: Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/showopen-webui
CVE-2026-44562Open WebUI: Model Import Overwrites Any Model Without Ownership Checkopen-webui
CVE-2026-44561Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channelsopen-webui
CVE-2026-44560Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Searchopen-webui
CVE-2026-44559Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channelsopen-webui
CVE-2026-44558Open WebUI: Channel Access Grants Bypass filter_allowed_access_grantsopen-webui
CVE-2026-44557Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collectionopen-webui
CVE-2026-44556Open WebUI: responses passthrough endpoint lacks access control authorizationopen-webui
CVE-2026-44555Open WebUI: Base Model Routing Bypasses Access Control via Model Chainingopen-webui
CVE-2026-44554Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwriteopen-webui
CVE-2026-44553Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Accessopen-webui
CVE-2026-44552Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache…open-webui
CVE-2026-44551Open WebUI: LDAP Empty Password Authentication Bypassopen-webui
CVE-2026-44550Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accountsopen-webui
CVE-2026-44549Open WebUI: Stored XSS in excel file previewopen-webui
CVE-2026-34225Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionalityopen-webui
CVE-2026-34222Open WebUI has Broken Access Control in Tool Valvesopen-webui
CVE-2026-29071Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memoriesopen-webui
CVE-2026-29070Open WebUI has unauthorized deletion of knowledge filesopen-webui
CVE-2026-28788Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwriteopen-webui
CVE-2026-28786Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`open-webui
CVE-2026-26193Open WebUI vulnerable to Stored XSS via iFrame embeds in response messagesopen-webui
CVE-2026-26192Open WebUI vulnerable to Stored XSS via iFrame in citations modelopen-webui
CVE-2025-65959Open WebUI vulnerable to Stored DOM XSS via Note 'Download PDF'open-webui
CVE-2025-65958Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in…open-webui
CVE-2025-64496Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Eventsopen-webui
CVE-2025-64495Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEopen-webui
CVE-2025-46719Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account…open-webui
CVE-2025-46571Open WebUI vulnerable to limited stored XSS vila uploaded html fileopen-webui
CVE-2024-8053Improper Authentication in open-webui/open-webuiopen-webui/open-webui
CVE-2024-8017Cross-site Scripting (XSS) in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7983Denial of Service in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7806Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webuiopen-webui open-webui/open-webui
CVE-2024-7049Exposure of Token in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7048IDOR in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7044Stored XSS in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7043Improper Access Control in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7041IDOR in open-webui/open-webuiopen-webui/open-webui
CVE-2024-7035Cross-Site Request Forgery (CSRF) in open-webui/open-webuiopen-webui/open-webui
CVE-2024-30256Open WebUI vulnerable to server-side request forgery in utils.pyopen-webui

156 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.