CVE-2025-63681
- EPSS 0.29%
- Veröffentlicht 04.12.2025 00:00:00
- Zuletzt bearbeitet 05.12.2025 20:15:57
open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
- EPSS 7.77%
- Veröffentlicht 08.11.2025 01:29:02
- Zuletzt bearbeitet 26.11.2025 15:36:09
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to exe...
CVE-2025-64495
- EPSS 0.46%
- Veröffentlicht 08.11.2025 01:25:48
- Zuletzt bearbeitet 26.11.2025 15:36:59
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 and below, the functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when 'Insert Prompt as Rich T...
CVE-2025-46719
- EPSS 0.52%
- Veröffentlicht 05.05.2025 18:50:56
- Zuletzt bearbeitet 17.06.2025 20:18:16
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a ch...
CVE-2025-46571
- EPSS 0.34%
- Veröffentlicht 05.05.2025 18:45:29
- Zuletzt bearbeitet 17.06.2025 20:18:30
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoi...
CVE-2025-29446
- EPSS 0.19%
- Veröffentlicht 21.04.2025 17:15:23
- Zuletzt bearbeitet 29.06.2026 20:16:51
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:11:31
- Zuletzt bearbeitet 21.07.2025 20:08:16
An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat ...
- EPSS 0.68%
- Veröffentlicht 20.03.2025 10:11:16
- Zuletzt bearbeitet 13.08.2026 15:19:00
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8053
- EPSS 0.62%
- Veröffentlicht 20.03.2025 10:11:13
- Zuletzt bearbeitet 27.03.2025 11:15:36
In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with ...
CVE-2024-7806
- EPSS 0.48%
- Veröffentlicht 20.03.2025 10:11:05
- Zuletzt bearbeitet 26.03.2025 16:46:35
A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the SameSite attribute set to lax for authentication and lacks CSRF to...