Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-webui — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in open-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting open-webui, a popular self-hosted LLM interface, focusing primarily on software weakness classes such as SQL injection, cross-site scripting, and improper access control. It collects known issues reported over the past three years, covering both critical and moderate severity flaws discovered through community reports and vendor advisories. Readers can use this hub to track the product's vulnerability history, understand recurring weakness patterns, and monitor how open-webui addresses security patches and configuration risks. The aggregation highlights common attack vectors relevant to self-hosted applications, helping administrators assess exposure without referencing individual CVE identifiers directly.

Vendor: open-webui

CVE ID Title CVSS Severity Published
CVE-2026-88006 Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange CWE-863 6.5 Medium 2026-09-10
CVE-2026-88005 Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange CWE-863 6.5 Medium 2026-09-10
CVE-2026-88002 Open WebUI: Any authenticated user can hang the server via a cyclic chat message history CWE-835 6.5 Medium 2026-09-09
CVE-2026-88001 Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets CWE-918 5.0 Medium 2026-09-09
CVE-2026-88000 Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree CWE-835 6.5 Medium 2026-09-09
CVE-2026-87999 Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch CWE-918 7.1 High 2026-09-09
CVE-2026-87998 Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion CWE-269 7.1 High 2026-09-09
CVE-2026-87997 Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions CWE-639 4.3 Medium 2026-09-09
CVE-2026-87996 Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader CWE-367 7.7 High 2026-09-09
CVE-2026-87995 Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin CWE-79 8.7 High 2026-09-09
CVE-2026-87994 Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint CWE-639 4.3 Medium 2026-09-09
CVE-2026-87017 Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends CWE-200 4.3 Medium 2026-09-09
CVE-2026-87016 Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite CWE-155 8.1 High 2026-09-09
CVE-2026-87015 Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication CWE-201 6.8 Medium 2026-09-09
CVE-2026-87014 Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes CWE-613 6.5 Medium 2026-09-09
CVE-2026-87013 Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle CWE-835 4.3 Medium 2026-09-09
CVE-2026-87012 Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value CWE-754 4.3 Medium 2026-09-09
CVE-2026-87011 Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout CWE-405 7.5 High 2026-09-09
CVE-2026-59714 Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) CWE-862 7.1 High 2026-08-13
CVE-2026-70494 Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder CWE-862 8.1 High 2026-08-04
CVE-2026-70493 Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically CWE-1333 6.5 Medium 2026-08-04
CVE-2026-70492 Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages CWE-79 8.7 High 2026-08-04
CVE-2026-70491 Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints CWE-200 6.5 Medium 2026-08-04
CVE-2026-70490 Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check CWE-863 6.3 Medium 2026-08-04
CVE-2026-70489 Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing CWE-400 6.5 Medium 2026-08-04
CVE-2026-54020 Open WebUI: DNS Rebinding SSRF Bypass CWE-367 6.3 Medium 2026-08-04
CVE-2026-70488 Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup CWE-639 4.3 Medium 2026-08-04
CVE-2026-70487 Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata CWE-862 5.3 Medium 2026-08-04
CVE-2026-70486 Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin CWE-79 8.2 High 2026-08-04
CVE-2026-70485 Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs CWE-918 7.1 High 2026-08-04

All 146 known CVE vulnerabilities affecting open-webui with full Chinese analysis, references, and POCs where available.