Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-webui — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in open-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting open-webui, a popular self-hosted LLM interface, focusing primarily on software weakness classes such as SQL injection, cross-site scripting, and improper access control. It collects known issues reported over the past three years, covering both critical and moderate severity flaws discovered through community reports and vendor advisories. Readers can use this hub to track the product's vulnerability history, understand recurring weakness patterns, and monitor how open-webui addresses security patches and configuration risks. The aggregation highlights common attack vectors relevant to self-hosted applications, helping administrators assess exposure without referencing individual CVE identifiers directly.

Vendor: open-webui

CVE ID Title CVSS Severity Published
CVE-2026-70484 Open WebUI: Users denied the image-generation permission can still generate images via chat completions CWE-862 4.3 Medium 2026-08-04
CVE-2026-70483 Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint CWE-862 3.1 Low 2026-08-04
CVE-2026-70482 Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client CWE-287 8.1 High 2026-08-04
CVE-2026-70481 Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages CWE-284 5.4 Medium 2026-08-04
CVE-2026-70480 Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering CWE-918 4.1 Medium 2026-08-04
CVE-2026-70479 Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader CWE-918 7.7 High 2026-08-04
CVE-2026-56400 open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation CWE-613 8.3 High 2026-07-15
CVE-2026-56398 Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI CWE-20 7.3 High 2026-07-15
CVE-2026-59221 open-webui terminal proxy path traversal guard bypass via 9x encoded traversal CWE-22 7.7 High 2026-07-09
CVE-2026-59225 Open WebUI: Arena task endpoints can bypass underlying model access controls CWE-862 5.4 Medium 2026-07-09
CVE-2026-59224 Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) CWE-287 8.0 High 2026-07-09
CVE-2026-59212 Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete CWE-863 5.4 Medium 2026-07-09
CVE-2026-59223 Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching CWE-693 4.3 Medium 2026-07-09
CVE-2026-59222 Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials CWE-200 - - 2026-07-09
CVE-2026-59215 Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding CWE-639 3.1 Low 2026-07-09
CVE-2026-59213 Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) CWE-524 3.5 Low 2026-07-09
CVE-2026-59217 Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) CWE-862 4.3 Medium 2026-07-09
CVE-2026-59216 Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id CWE-94 7.7 High 2026-07-09
CVE-2026-59219 Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout CWE-613 7.1 High 2026-07-09
CVE-2026-59715 Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave) CWE-306 3.1 Low 2026-07-09
CVE-2026-59220 Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config CWE-1333 6.5 Medium 2026-07-09
CVE-2026-59226 Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation CWE-285 3.1 Low 2026-07-09
CVE-2026-59227 Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission CWE-862 4.3 Medium 2026-07-09
CVE-2026-59218 Open WebUI: Account enumeration via observable login timing discrepancy CWE-208 5.3 Medium 2026-07-09
CVE-2026-59214 Open WebUI: Stored web worker XSS via Pyodide CWE-79 7.3 High 2026-07-09
CVE-2026-56399 Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/web CWE-918 5.0 Medium 2026-06-30
CVE-2026-54007 Open WebUI: Cross-origin postMessage confirmation bypass via action:submit CWE-346 - - 2026-06-23
CVE-2026-54006 Open WebUI: Calendar event re-parenting allows writing events into another user's calendar CWE-639 4.3 Medium 2026-06-23
CVE-2026-54008 Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` CWE-918 8.5 High 2026-06-23
CVE-2026-54009 Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field CWE-639 6.5 Medium 2026-06-23

All 146 known CVE vulnerabilities affecting open-webui with full Chinese analysis, references, and POCs where available.