Open WebUI是Open WebUI团队开源的一个可扩展、功能丰富、用户友好的自托管 WebUI。 Open WebUI 0.9.6之前版本存在安全漏洞,该漏洞源于提示版本历史端点未验证历史记录是否属于指定提示,可能导致经过身份验证的用户读取或删除其他用户的私有提示历史。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| open-webui | open-webui | < 0.9.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-webui | open-webui | < 0.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54011 | 8.7 HIGH | Open WebUI: Stored XSS in Mermaid Markdown Preview |
| CVE-2026-54008 | 8.5 HIGH | Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` |
| CVE-2026-54010 | 8.3 HIGH | Open WebUI: Forged chat-file link allows cross-user file read and deletion |
| CVE-2026-54018 | 7.7 HIGH | Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects |
| CVE-2026-54013 | 7.6 HIGH | Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI |
| CVE-2026-54012 | 7.1 HIGH | Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion |
| CVE-2026-54009 | 6.5 MEDIUM | Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field |
| CVE-2026-54019 | 6.5 MEDIUM | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode |
| CVE-2026-54021 | 6.3 MEDIUM | Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguar |
| CVE-2026-54022 | 5.3 MEDIUM | Open WebUI: Any authenticated user can read other users' private notes via Socket.IO |
| CVE-2026-54016 | 4.3 MEDIUM | Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base F |
| CVE-2026-54006 | 4.3 MEDIUM | Open WebUI: Calendar event re-parenting allows writing events into another user's calendar |
| CVE-2026-54014 | 4.3 MEDIUM | Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui |
| CVE-2026-54007 | Open WebUI: Cross-origin postMessage confirmation bypass via action:submit |
No comments yet