Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-webui — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in open-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting open-webui, a popular self-hosted LLM interface, focusing primarily on software weakness classes such as SQL injection, cross-site scripting, and improper access control. It collects known issues reported over the past three years, covering both critical and moderate severity flaws discovered through community reports and vendor advisories. Readers can use this hub to track the product's vulnerability history, understand recurring weakness patterns, and monitor how open-webui addresses security patches and configuration risks. The aggregation highlights common attack vectors relevant to self-hosted applications, helping administrators assess exposure without referencing individual CVE identifiers directly.

Vendor: open-webui

CVE ID Title CVSS Severity Published
CVE-2026-54010 Open WebUI: Forged chat-file link allows cross-user file read and deletion CWE-284 8.3 High 2026-06-23
CVE-2026-54011 Open WebUI: Stored XSS in Mermaid Markdown Preview CWE-79 8.7 High 2026-06-23
CVE-2026-54012 Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion CWE-284 7.1 High 2026-06-23
CVE-2026-54013 Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI CWE-79 7.6 High 2026-06-23
CVE-2026-54014 Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui CWE-22 4.3 Medium 2026-06-23
CVE-2026-54015 Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion CWE-284 6.4 Medium 2026-06-23
CVE-2026-54016 Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration CWE-639 4.3 Medium 2026-06-23
CVE-2026-54018 Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects CWE-918 7.7 High 2026-06-23
CVE-2026-54019 Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode CWE-862 6.5 Medium 2026-06-23
CVE-2026-54021 Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter CWE-863 6.3 Medium 2026-06-23
CVE-2026-54022 Open WebUI: Any authenticated user can read other users' private notes via Socket.IO CWE-706 5.3 Medium 2026-06-23
CVE-2026-54017 Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal CWE-22 7.7 High 2026-06-18
CVE-2026-45338 Open WebUI: SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py) CWE-918 7.7 High 2026-05-15
CVE-2026-44549 Open WebUI: Stored XSS in excel file preview CWE-79 7.3 High 2026-05-15
CVE-2026-45299 Open WebUI: Stored Cross-Site Scripting In Profile Picture CWE-79 5.4 Medium 2026-05-15
CVE-2026-45665 Open WebUI: Stored XSS in Banner Component via Improper Sanitization Order CWE-79 8.1 High 2026-05-15
CVE-2026-45667 Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS) CWE-862 6.5 Medium 2026-05-15
CVE-2026-44565 Open WebUI: Open WebUI Arbitrary File Write, Delete via Path Traversal CWE-22 8.1 High 2026-05-15
CVE-2026-45314 Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image CWE-87 - - 2026-05-15
CVE-2026-45316 Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access) CWE-863 3.5 Low 2026-05-15
CVE-2026-45317 Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation CWE-20 4.6 Medium 2026-05-15
CVE-2026-45318 Open WebUI: Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify) CWE-79 5.4 Medium 2026-05-15
CVE-2026-45315 Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions CWE-79 8.7 High 2026-05-15
CVE-2026-44571 Open WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read Permission CWE-862 6.5 Medium 2026-05-15
CVE-2026-45350 Open WebUI: Chat completion API allows tool restrictions to be bypassed CWE-862 7.1 High 2026-05-15
CVE-2026-45303 Open WebUI: Stored XSS via the HTML renedering view CWE-79 7.7 High 2026-05-15
CVE-2026-45301 Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file CWE-284 8.1 High 2026-05-15
CVE-2026-45345 Open WebUI: Missing authorization check at the model update function - models from other users can be updated CWE-285 6.5 Medium 2026-05-15
CVE-2026-45346 Open WebUI: Stored Cross-Site Scripting in SVG Renderer CWE-80 - - 2026-05-15
CVE-2026-45347 Open WebUI: Blind server side request forgery (SSRF) via the PDF generate function CWE-918 4.3 Medium 2026-05-15

All 146 known CVE vulnerabilities affecting open-webui with full Chinese analysis, references, and POCs where available.