Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: open-webui Clear
ID Title
CVE-2026-56398 Vulnerability in openwebui (CVE-2026-56398)
vulnerability in openwebui (CVE-2026-56398). Confidential information can be exposed externally.
CVE-2026-56400 Vulnerability in openwebui (CVE-2026-56400)
vulnerability in openwebui (CVE-2026-56400). Successful exploitation can lead to full system takeover.
CVE-2026-59221 Path Traversal in open-webui (CVE-2026-59221)
path traversal in open-webui (CVE-2026-59221). Confidential information can be exposed externally. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59715 Vulnerability in open-webui (CVE-2026-59715)
vulnerability in open-webui (CVE-2026-59715). Risk of unauthorized operations or information disclosure. Exploitable via ``connect``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59227 Vulnerability in open-webui (CVE-2026-59227)
vulnerability in open-webui (CVE-2026-59227). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/images/edit`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59226 Vulnerability in open-webui (CVE-2026-59226)
vulnerability in open-webui (CVE-2026-59226). Risk of unauthorized operations or information disclosure. Exploitable via ``pending``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59220 Vulnerability in open-webui (CVE-2026-59220)
vulnerability in open-webui (CVE-2026-59220). Risk of unauthorized operations or information disclosure. Exploitable via ``SKILL_MENTION_RE``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59222 Information Disclosure in open-webui (CVE-2026-59222)
vulnerability in open-webui (CVE-2026-59222). Confidential information can be exposed externally. Exploitable via ``UserModel``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59223 Vulnerability in open-webui (CVE-2026-59223)
vulnerability in open-webui (CVE-2026-59223). Risk of unauthorized operations or information disclosure. Exploitable via ``WEB_FETCH_FILTER_LIST``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59224 Authentication Bypass in open-webui (CVE-2026-59224)
authentication bypass in open-webui (CVE-2026-59224). Successful exploitation can lead to full system takeover. Exploitable via ``proxy_terminal``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59225 Vulnerability in open-webui (CVE-2026-59225)
vulnerability in open-webui (CVE-2026-59225). Risk of unauthorized operations or information disclosure. Exploitable via ``selected_model_id``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59219 Vulnerability in open-webui (CVE-2026-59219)
vulnerability in open-webui (CVE-2026-59219). Confidential information can be exposed externally. Exploitable via `POST /api/v1/auths/signout`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59218 Vulnerability in open-webui (CVE-2026-59218)
vulnerability in open-webui (CVE-2026-59218). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59217 Vulnerability in open-webui (CVE-2026-59217)
vulnerability in open-webui (CVE-2026-59217). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge/`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59216 Code Injection in open-webui (CVE-2026-59216)
code injection in open-webui (CVE-2026-59216). Confidential information can be exposed externally. Exploitable via `POST /api/v1/chat/completions`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59215 Vulnerability in open-webui (CVE-2026-59215)
vulnerability in open-webui (CVE-2026-59215). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/channels/{id}/messages/{message_id}/thread`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59214 Cross-Site Scripting (XSS) in open-webui (CVE-2026-59214)
cross-site scripting in open-webui (CVE-2026-59214). Confidential information can be exposed externally. Exploitable via ``pyodide.http.pyfetch``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59213 Vulnerability in open-webui (CVE-2026-59213)
vulnerability in open-webui (CVE-2026-59213). Risk of unauthorized operations or information disclosure. Exploitable via ``get_all_models``. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-59212 Authorization Flaw in open-webui (CVE-2026-59212)
vulnerability in open-webui (CVE-2026-59212). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/files/{id}/rename`. Mitigation: upgrade to `0.10.0` or later.
CVE-2026-54022 Vulnerability in open-webui (CVE-2026-54022)
vulnerability in open-webui (CVE-2026-54022). Confidential information can be exposed externally. Exploitable via ``document_id``. Mitigation: upgrade to `0.8.11` or later.
CVE-2026-54021 Authorization Flaw in open-webui (CVE-2026-54021)
vulnerability in open-webui (CVE-2026-54021). Risk of unauthorized operations or information disclosure. Exploitable via `POST /ollama/api/chat/{url_idx}`. Mitigation: upgrade to `>= 0.9.6` or later.
CVE-2026-54019 Vulnerability in open-webui (CVE-2026-54019)
vulnerability in open-webui (CVE-2026-54019). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/query/collection`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54018 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54018)
SSRF in open-webui (CVE-2026-54018). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54017 Path Traversal in open-webui (CVE-2026-54017)
path traversal in open-webui (CVE-2026-54017). Confidential information can be exposed externally. Exploitable via `GET /api/v1/terminals/server1/..`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54016 Vulnerability in open-webui (CVE-2026-54016)
vulnerability in open-webui (CVE-2026-54016). Risk of unauthorized operations or information disclosure. Exploitable via ``search_knowledge_files``. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54015 Vulnerability in open-webui (CVE-2026-54015)
vulnerability in open-webui (CVE-2026-54015). Confidential information can be exposed externally. Exploitable via `GET /api/v1/prompts/id/{prompt_id}/history/diff`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54014 Path Traversal in open-webui (CVE-2026-54014)
path traversal in open-webui (CVE-2026-54014). Risk of unauthorized operations or information disclosure. Exploitable via `GET /cache/{{path}}`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54013 Cross-Site Scripting (XSS) in open-webui (CVE-2026-54013)
cross-site scripting in open-webui (CVE-2026-54013). Confidential information can be exposed externally. Exploitable via `GET /api/v1/models/model/profile/image`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54012 Vulnerability in open-webui (CVE-2026-54012)
vulnerability in open-webui (CVE-2026-54012). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54011 Cross-Site Scripting (XSS) in open-webui (CVE-2026-54011)
cross-site scripting in open-webui (CVE-2026-54011). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54010 Vulnerability in open-webui (CVE-2026-54010)
vulnerability in open-webui (CVE-2026-54010). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `>= 0.9.6` or later.
CVE-2026-54009 Vulnerability in open-webui (CVE-2026-54009)
vulnerability in open-webui (CVE-2026-54009). Confidential information can be exposed externally. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54008 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54008)
SSRF in open-webui (CVE-2026-54008). Confidential information can be exposed externally. Exploitable via `GET /api/v1/auths/`. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-54007 Vulnerability in open-webui (CVE-2026-54007)
vulnerability in open-webui (CVE-2026-54007). Data can be tampered with by attackers. Exploitable via `POST /api/v1/chats/new`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54006 Vulnerability in open-webui (CVE-2026-54006)
vulnerability in open-webui (CVE-2026-54006). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/calendars/events/{event_id}/update`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-45675 Privilege Escalation in open-webui (CVE-2026-45675)
vulnerability in open-webui (CVE-2026-45675). Successful exploitation can lead to full system takeover. Exploitable via ``signup_handler``. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45672 Authorization Flaw in open-webui (CVE-2026-45672)
vulnerability in open-webui (CVE-2026-45672). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.12` or later.
CVE-2026-45671 Vulnerability in open-webui (CVE-2026-45671)
vulnerability in open-webui (CVE-2026-45671). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /api/v1/files/{id}`. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45667 Vulnerability in open-webui (CVE-2026-45667)
vulnerability in open-webui (CVE-2026-45667). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-45666 Vulnerability in open-webui (CVE-2026-45666)
vulnerability in open-webui (CVE-2026-45666). Confidential information can be exposed externally. Exploitable via `GET /api/config.`. Mitigation: upgrade to `0.8.11` or later.
CVE-2026-45665 Cross-Site Scripting (XSS) in open-webui (CVE-2026-45665)
cross-site scripting in open-webui (CVE-2026-45665). Confidential information can be exposed externally. Exploitable via ``marked.parse``. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-45402 Vulnerability in open-webui (CVE-2026-45402)
vulnerability in open-webui (CVE-2026-45402). Confidential information can be exposed externally. Exploitable via `POST /api/v1/folders/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45401 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45401)
SSRF in open-webui (CVE-2026-45401). Confidential information can be exposed externally. Exploitable via ``requests``. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45400 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45400)
SSRF in open-webui (CVE-2026-45400). Confidential information can be exposed externally. Exploitable via ``requests``. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45399 Vulnerability in open-webui (CVE-2026-45399)
vulnerability in open-webui (CVE-2026-45399). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/tasks`. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45398 Vulnerability in open-webui (CVE-2026-45398)
vulnerability in open-webui (CVE-2026-45398). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/retrieval/query/doc`. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45397 Vulnerability in open-webui (CVE-2026-45397)
vulnerability in open-webui (CVE-2026-45397). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/retrieval/`. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45396 Vulnerability in open-webui (CVE-2026-45396)
vulnerability in open-webui (CVE-2026-45396). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/evaluations/feedback`. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45395 Privilege Escalation in open-webui (CVE-2026-45395)
vulnerability in open-webui (CVE-2026-45395). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/tools/id/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45387 Information Disclosure in open-webui (CVE-2026-45387)
vulnerability in open-webui (CVE-2026-45387). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.5` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →