All 10 CVE vulnerabilities found in open-webui/open-webui, with AI-generated Chinese analysis, references, and POCs.
This page documents known vulnerabilities for the open-webui/open-webui product, categorized under weakness types associated with web interface security flaws. It aggregates reported security issues to provide a comprehensive overview of the product's risk landscape, covering data ranging from initial reports to recent patch releases. Here, users can track the vendor's security advisories to stay informed about critical updates, understand the implications of specific weakness classes within the context of this open-source web UI, and look up the product's vulnerability history to assess long-term maintenance quality. The collection aims to offer transparency into the security posture of open-webui, facilitating informed decision-making for developers and system administrators who rely on this tool for local large language model deployment. By centralizing these details, the page helps mitigate risks associated with unpatched or misconfigured installations. It serves as a reference point for auditing the software against common attack vectors, including but not limited to authentication bypasses, data exposure, and command injection. Readers are encouraged to cross-reference this data with official vendor channels for the most current remediation steps. The information presented is derived from various sources, ensuring a broad perspective on the threats facing the project. This resource does not endorse any specific security tool but rather provides factual data to support independent security analysis. Keeping this page updated ensures that stakeholders have access to timely and accurate information regarding the integrity and safety of the open-webui environment.
Vendor: open-webui
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-8017 | Cross-site Scripting (XSS) in open-webui/open-webui CWE-79 | 5.4 | - | 2025-03-20 |
| CVE-2024-8053 | Improper Authentication in open-webui/open-webui CWE-306 | 9.1 | - | 2025-03-20 |
| CVE-2024-7806 | Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webui CWE-352 | 8.8 | - | 2025-03-20 |
| CVE-2024-7043 | Improper Access Control in open-webui/open-webui CWE-862 | 9.8 | - | 2025-03-20 |
| CVE-2024-7983 | Denial of Service in open-webui/open-webui CWE-770 | 7.5 | - | 2025-03-20 |
| CVE-2024-7044 | Stored XSS in open-webui/open-webui CWE-79 | 6.1 | - | 2025-03-20 |
| CVE-2024-7035 | Cross-Site Request Forgery (CSRF) in open-webui/open-webui CWE-352 | 8.1 | - | 2025-03-20 |
| CVE-2024-7049 | Exposure of Token in open-webui/open-webui CWE-488 | 8.1AI | HighAI | 2024-10-10 |
| CVE-2024-7048 | IDOR in open-webui/open-webui CWE-863 | 8.8AI | HighAI | 2024-10-10 |
| CVE-2024-7041 | IDOR in open-webui/open-webui CWE-639 | 4.3AI | MediumAI | 2024-10-09 |
All 10 known CVE vulnerabilities affecting open-webui/open-webui with full Chinese analysis, references, and POCs where available.