Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-webui — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in open-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting open-webui, a popular self-hosted LLM interface, focusing primarily on software weakness classes such as SQL injection, cross-site scripting, and improper access control. It collects known issues reported over the past three years, covering both critical and moderate severity flaws discovered through community reports and vendor advisories. Readers can use this hub to track the product's vulnerability history, understand recurring weakness patterns, and monitor how open-webui addresses security patches and configuration risks. The aggregation highlights common attack vectors relevant to self-hosted applications, helping administrators assess exposure without referencing individual CVE identifiers directly.

Vendor: open-webui

CVE ID Title CVSS Severity Published
CVE-2026-45351 Open WebUI: Exposure of System Prompt to Regular User [Non-Admin] CWE-200 6.5 Medium 2026-05-15
CVE-2026-45666 Open WebUI: Indirect Object Reference (IDOR) in user notes CWE-639 6.5 Medium 2026-05-15
CVE-2026-45365 Open WebUI: Authenticated users can bypass model access control via exposed query parameter CWE-285 5.4 Medium 2026-05-15
CVE-2026-44570 Open WebUI: Inconsistent authorization controls within memories API CWE-639 8.3 High 2026-05-15
CVE-2026-44569 Open WebUI: Insecure Message Access Breaks Authorization CWE-862 7.1 High 2026-05-15
CVE-2026-44566 Open WebUI: Arbitrary File Upload and Path Traversal CWE-22 7.3 High 2026-05-15
CVE-2026-44567 Open WebUI: Open WebUI Improper Authorization Control CWE-863 7.3 High 2026-05-15
CVE-2026-45672 Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed CWE-863 8.8 High 2026-05-15
CVE-2026-45400 Open WebUI: Server-Side Request Forgery (SSRF) bypass in `validate_url` CWE-918 8.5 High 2026-05-15
CVE-2026-45402 Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints CWE-639 8.1 High 2026-05-15
CVE-2026-45401 Open WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints CWE-918 8.5 High 2026-05-15
CVE-2026-45386 Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint CWE-639 4.3 Medium 2026-05-15
CVE-2026-45398 Open WebUI: IDOR - Retrieval API Bypasses Knowledge Base Access Controls CWE-639 7.5 High 2026-05-15
CVE-2026-45397 Open WebUI: Unauthenticated RAG Configuration Disclosure CWE-306 5.3 Medium 2026-05-15
CVE-2026-45396 Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation CWE-915 5.4 Medium 2026-05-15
CVE-2026-45395 Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution CWE-269 7.2 High 2026-05-15
CVE-2026-45387 Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage) CWE-200 4.3 Medium 2026-05-15
CVE-2026-45385 Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint CWE-639 4.3 Medium 2026-05-15
CVE-2026-44721 Open WebUI: Stored XSS via Model Description CWE-79 7.3 High 2026-05-15
CVE-2026-44550 Open WebUI: Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts CWE-862 5.0 Medium 2026-05-15
CVE-2026-44551 Open WebUI: LDAP Empty Password Authentication Bypass CWE-287 9.1 Critical 2026-05-15
CVE-2026-44552 Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning CWE-668 8.7 High 2026-05-15
CVE-2026-44553 Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access CWE-613 8.1 High 2026-05-15
CVE-2026-44554 Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite CWE-862 8.1 High 2026-05-15
CVE-2026-44555 Open WebUI: Base Model Routing Bypasses Access Control via Model Chaining CWE-862 7.6 High 2026-05-15
CVE-2026-44556 Open WebUI: responses passthrough endpoint lacks access control authorization CWE-284 7.1 High 2026-05-15
CVE-2026-44557 Open WebUI: Global Knowledge Base Enumeration via knowledge-bases Meta-Collection CWE-863 4.3 Medium 2026-05-15
CVE-2026-44558 Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants CWE-862 5.4 Medium 2026-05-15
CVE-2026-44559 Open WebUI: Missing Access Check on Channel Members Endpoint for Standard Channels CWE-862 4.3 Medium 2026-05-15
CVE-2026-44560 Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Search CWE-862 6.5 Medium 2026-05-15

All 146 known CVE vulnerabilities affecting open-webui with full Chinese analysis, references, and POCs where available.