Openwebui

Open Webui

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 04.08.2026 20:56:20
  • Zuletzt bearbeitet 05.08.2026 15:17:12

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participa...

  • EPSS 0.27%
  • Veröffentlicht 04.08.2026 20:16:55
  • Zuletzt bearbeitet 05.08.2026 16:17:02

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generati...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 15.07.2026 11:25:31
  • Zuletzt bearbeitet 16.07.2026 20:03:11

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui ins...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 15.07.2026 11:25:30
  • Zuletzt bearbeitet 16.07.2026 20:03:37

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the prof...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 17:43:06

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objects for channel members, including settings.ui.toolServers[].key and web...

  • EPSS 0.22%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 17:39:40

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_LIST matching compared configured host entries against URL strings and non-label-boundary suffixes, allowing path-based blocklist ...

  • EPSS 0.29%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 15:22:04

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, ...

  • EPSS 0.21%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 02:44:19

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 10.07.2026 19:49:23

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permis...

  • EPSS 0.26%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 13.07.2026 12:27:12

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message fr...