Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 10.09.2026 14:43:17
  • Zuletzt bearbeitet 18.09.2026 14:43:56

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the ...

  • EPSS 0.22%
  • Veröffentlicht 10.09.2026 14:38:52
  • Zuletzt bearbeitet 18.09.2026 14:44:04

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.09.2026 21:40:06
  • Zuletzt bearbeitet 14.09.2026 19:56:27

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.09.2026 21:38:05
  • Zuletzt bearbeitet 14.09.2026 19:56:01

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when AIOHTTP_CLIENT...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.09.2026 21:35:25
  • Zuletzt bearbeitet 14.09.2026 17:48:49

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to follow chil...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.09.2026 21:33:18
  • Zuletzt bearbeitet 16.09.2026 15:13:49

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's glob...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.09.2026 21:31:48
  • Zuletzt bearbeitet 16.09.2026 15:14:19

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then re...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 21:30:09
  • Zuletzt bearbeitet 16.09.2026 15:14:39

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id into a new c...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 21:28:10
  • Zuletzt bearbeitet 16.09.2026 15:14:48

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwr...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.09.2026 21:26:30
  • Zuletzt bearbeitet 16.09.2026 15:14:57

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts and a...