CVE-2026-54007
- EPSS 0.16%
- Veröffentlicht 23.06.2026 16:51:27
- Zuletzt bearbeitet 25.06.2026 13:40:33
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the chat message listener allows non-same-origin input:prompt and action:submit messages, so an external site can set prompt text and t...
CVE-2026-54006
- EPSS 0.18%
- Veröffentlicht 23.06.2026 16:50:44
- Zuletzt bearbeitet 25.06.2026 13:41:57
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/v1/calendars/events/{event_id}/update validates that the caller has write access to the calendar the event currently belongs ...
CVE-2026-54008
- EPSS 0.2%
- Veröffentlicht 23.06.2026 16:50:06
- Zuletzt bearbeitet 25.06.2026 13:35:46
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.C...
CVE-2026-54009
- EPSS 0.23%
- Veröffentlicht 23.06.2026 16:49:13
- Zuletzt bearbeitet 25.06.2026 13:35:03
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url value that, when it does NOT start with http://, https://, or data:image/, is inter...
CVE-2026-54010
- EPSS 0.24%
- Veröffentlicht 23.06.2026 16:48:22
- Zuletzt bearbeitet 25.06.2026 13:34:24
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or ca...
CVE-2026-54011
- EPSS 0.2%
- Veröffentlicht 23.06.2026 16:47:43
- Zuletzt bearbeitet 25.06.2026 13:33:32
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using innerHT...
CVE-2026-54012
- EPSS 0.2%
- Veröffentlicht 23.06.2026 16:47:03
- Zuletzt bearbeitet 25.06.2026 13:26:51
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their model without...
CVE-2026-54013
- EPSS 0.17%
- Veröffentlicht 23.06.2026 16:46:28
- Zuletzt bearbeitet 25.06.2026 13:06:43
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. ...
CVE-2026-54014
- EPSS 0.24%
- Veröffentlicht 23.06.2026 16:45:39
- Zuletzt bearbeitet 25.06.2026 14:36:17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a path traversal vulnerability exists in open-webui's cache file serving endpoint that allows any authenticated user to read files from...
CVE-2026-54015
- EPSS 0.17%
- Veröffentlicht 23.06.2026 16:44:57
- Zuletzt bearbeitet 25.06.2026 14:35:30
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-history endpoints authorize the prompt_id in the URL but then act on caller-supplied history IDs without ve...