Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Veröffentlicht 15.05.2026 20:35:35
  • Zuletzt bearbeitet 19.05.2026 12:18:19

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name prefixes but does not check knowledge base collection...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 15.05.2026 20:34:23
  • Zuletzt bearbeitet 19.05.2026 12:19:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 20:33:47
  • Zuletzt bearbeitet 19.05.2026 12:20:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 15.05.2026 20:33:02
  • Zuletzt bearbeitet 19.05.2026 03:05:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspace.tools permission check that is present on the too...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 15.05.2026 20:32:02
  • Zuletzt bearbeitet 19.05.2026 03:05:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, when setting model permissions so that a group has read access to it, intending for other users to use it, those users also can read th...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 15.05.2026 20:29:36
  • Zuletzt bearbeitet 19.05.2026 01:45:35

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, an IDOR vulnerability exists in the Channels feature of Open WebUI, allowing any channel member to modify messages sent by other member...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 20:02:16
  • Zuletzt bearbeitet 19.05.2026 14:16:45

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a stored cross-site scripting (XSS) vulnerability that allows any authenticated user with model creation permission (workspace.models) ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 15.05.2026 20:00:59
  • Zuletzt bearbeitet 19.05.2026 03:12:01

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fields to pass through Pydantic validation and be inc...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 15.05.2026 19:59:35
  • Zuletzt bearbeitet 18.05.2026 18:35:23

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 19:57:22
  • Zuletzt bearbeitet 18.05.2026 18:32:33

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis datab...