Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

open-webui — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in open-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting open-webui, a popular self-hosted LLM interface, focusing primarily on software weakness classes such as SQL injection, cross-site scripting, and improper access control. It collects known issues reported over the past three years, covering both critical and moderate severity flaws discovered through community reports and vendor advisories. Readers can use this hub to track the product's vulnerability history, understand recurring weakness patterns, and monitor how open-webui addresses security patches and configuration risks. The aggregation highlights common attack vectors relevant to self-hosted applications, helping administrators assess exposure without referencing individual CVE identifiers directly.

Vendor: open-webui

CVE ID Title CVSS Severity Published
CVE-2026-44561 Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels CWE-863 5.4 Medium 2026-05-15
CVE-2026-44562 Open WebUI: Model Import Overwrites Any Model Without Ownership Check CWE-862 6.5 Medium 2026-05-15
CVE-2026-44563 Open WebUI: Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show CWE-862 5.4 Medium 2026-05-15
CVE-2026-44564 Open WebUI: Read-Only Users Can Modify Collaborative Documents via Socket.IO CWE-863 5.4 Medium 2026-05-15
CVE-2026-44568 Open WebUI: Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order CWE-79 4.8 Medium 2026-05-15
CVE-2026-45331 Open WebUI: Full SSRF Vulnerability in the RAG Web Search Feature CWE-918 8.5 High 2026-05-15
CVE-2026-45339 Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints CWE-863 6.5 Medium 2026-05-15
CVE-2026-45349 Open WebUI: Broken Access Control for Completions API CWE-639 7.1 High 2026-05-15
CVE-2026-45399 Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption CWE-862 7.1 High 2026-05-15
CVE-2026-45671 Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion CWE-639 8.0 High 2026-05-15
CVE-2026-45675 Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts CWE-269 8.1 High 2026-05-15
CVE-2026-34225 Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality CWE-918 4.3 Medium 2026-04-14
CVE-2026-34222 Open WebUI has Broken Access Control in Tool Valves CWE-285 7.7 High 2026-04-01
CVE-2026-29071 Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories CWE-639 3.1 Low 2026-03-26
CVE-2026-29070 Open WebUI has unauthorized deletion of knowledge files CWE-862 5.4 Medium 2026-03-26
CVE-2026-28788 Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite CWE-639 7.1 High 2026-03-26
CVE-2026-28786 Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions` CWE-22 4.3 Medium 2026-03-26
CVE-2026-26193 Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages CWE-79 7.3 High 2026-02-19
CVE-2026-26192 Open WebUI vulnerable to Stored XSS via iFrame in citations model CWE-79 7.3 High 2026-02-19
CVE-2025-65959 Open WebUI vulnerable to Stored DOM XSS via Note 'Download PDF' CWE-79 8.7 High 2025-12-04
CVE-2025-65958 Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web CWE-918 8.5 High 2025-12-04
CVE-2025-64496 Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events CWE-95 7.3 High 2025-11-08
CVE-2025-64495 Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE CWE-79 8.7 High 2025-11-08
CVE-2025-46719 Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions CWE-79 8.2AI High AI 2025-05-05
CVE-2025-46571 Open WebUI vulnerable to limited stored XSS vila uploaded html file CWE-79 5.4AI Medium AI 2025-05-05
CVE-2024-30256 Open WebUI vulnerable to server-side request forgery in utils.py CWE-918 6.4 Medium 2024-04-16

All 146 known CVE vulnerabilities affecting open-webui with full Chinese analysis, references, and POCs where available.