CVE-2026-44563
- EPSS 0.24%
- Veröffentlicht 15.05.2026 19:28:25
- Zuletzt bearbeitet 19.05.2026 03:11:24
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any model name from the user and forward the request to ...
CVE-2026-44564
- EPSS 0.22%
- Veröffentlicht 15.05.2026 19:26:24
- Zuletzt bearbeitet 19.05.2026 03:11:43
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a member of the document's Socket.IO room (line 678) but ...
CVE-2026-44568
- EPSS 0.17%
- Veröffentlicht 15.05.2026 19:24:46
- Zuletzt bearbeitet 19.05.2026 03:06:13
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overlay Content" using marked.parse() inside {@html} wit...
CVE-2026-45331
- EPSS 0.29%
- Veröffentlicht 15.05.2026 19:22:58
- Zuletzt bearbeitet 19.05.2026 03:06:35
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip, private=True), but the validators library does NO...
CVE-2026-45339
- EPSS 0.31%
- Veröffentlicht 15.05.2026 19:21:26
- Zuletzt bearbeitet 19.05.2026 03:07:48
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from /api/v1/messages, re...
CVE-2026-45349
- EPSS 0.23%
- Veröffentlicht 15.05.2026 19:20:37
- Zuletzt bearbeitet 19.05.2026 14:16:45
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API endpoint: /api/chat/completions with their own API key (generated in OWUI) and the Chat ID of another ...
CVE-2026-45399
- EPSS 0.27%
- Veröffentlicht 15.05.2026 19:18:06
- Zuletzt bearbeitet 19.05.2026 03:08:17
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks across the system and stop tasks belonging to other us...
- EPSS 0.27%
- Veröffentlicht 15.05.2026 19:13:42
- Zuletzt bearbeitet 19.05.2026 03:08:53
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE /api/v1/files/{id} when the target file is referenc...
CVE-2026-45675
- EPSS 0.35%
- Veröffentlicht 15.05.2026 19:12:57
- Zuletzt bearbeitet 19.05.2026 14:16:46
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regul...
CVE-2026-34225
- EPSS 0.29%
- Veröffentlicht 14.04.2026 01:39:07
- Zuletzt bearbeitet 21.04.2026 23:31:23
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allows editing an image via a prompt. The affected funct...