CVE-2026-88006
- EPSS 0.22%
- Veröffentlicht 10.09.2026 14:43:17
- Zuletzt bearbeitet 18.09.2026 14:43:56
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the ...
CVE-2026-88005
- EPSS 0.22%
- Veröffentlicht 10.09.2026 14:38:52
- Zuletzt bearbeitet 18.09.2026 14:44:04
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the...
CVE-2026-88002
- EPSS 0.31%
- Veröffentlicht 09.09.2026 21:40:06
- Zuletzt bearbeitet 14.09.2026 19:56:27
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tracked visited ...
- EPSS 0.27%
- Veröffentlicht 09.09.2026 21:38:05
- Zuletzt bearbeitet 14.09.2026 19:56:01
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when AIOHTTP_CLIENT...
CVE-2026-88000
- EPSS 0.31%
- Veröffentlicht 09.09.2026 21:35:25
- Zuletzt bearbeitet 14.09.2026 17:48:49
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to follow chil...
CVE-2026-87999
- EPSS 0.22%
- Veröffentlicht 09.09.2026 21:33:18
- Zuletzt bearbeitet 16.09.2026 15:13:49
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's glob...
CVE-2026-87998
- EPSS 0.27%
- Veröffentlicht 09.09.2026 21:31:48
- Zuletzt bearbeitet 16.09.2026 15:14:19
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then re...
CVE-2026-87997
- EPSS 0.21%
- Veröffentlicht 09.09.2026 21:30:09
- Zuletzt bearbeitet 16.09.2026 15:14:39
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id into a new c...
CVE-2026-87996
- EPSS 0.21%
- Veröffentlicht 09.09.2026 21:28:10
- Zuletzt bearbeitet 16.09.2026 15:14:48
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwr...
CVE-2026-87995
- EPSS 0.22%
- Veröffentlicht 09.09.2026 21:26:30
- Zuletzt bearbeitet 16.09.2026 15:14:57
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox containing both allow-scripts and a...