CVE-2026-87994
- EPSS 0.21%
- Veröffentlicht 09.09.2026 21:24:55
- Zuletzt bearbeitet 16.09.2026 15:15:32
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a supplied mess...
CVE-2026-87017
- EPSS 0.21%
- Veröffentlicht 09.09.2026 21:23:27
- Zuletzt bearbeitet 16.09.2026 15:23:05
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in ...
CVE-2026-87016
- EPSS 0.33%
- Veröffentlicht 09.09.2026 21:21:43
- Zuletzt bearbeitet 15.09.2026 15:29:13
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to ...
CVE-2026-87013
- EPSS 0.27%
- Veröffentlicht 09.09.2026 21:17:06
- Zuletzt bearbeitet 15.09.2026 16:09:34
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the folder tree wal...
CVE-2026-87014
- EPSS 0.28%
- Veröffentlicht 09.09.2026 21:17:06
- Zuletzt bearbeitet 15.09.2026 15:56:08
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role ...
CVE-2026-87015
- EPSS 0.28%
- Veröffentlicht 09.09.2026 21:17:06
- Zuletzt bearbeitet 15.09.2026 15:54:14
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each external tool cal...
CVE-2026-87012
- EPSS 0.27%
- Veröffentlicht 09.09.2026 20:57:58
- Zuletzt bearbeitet 15.09.2026 16:17:55
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-ev...
CVE-2026-87011
- EPSS 0.34%
- Veröffentlicht 09.09.2026 20:54:26
- Zuletzt bearbeitet 15.09.2026 16:26:18
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and sig...
CVE-2026-70494
- EPSS 0.3%
- Veröffentlicht 04.08.2026 20:58:05
- Zuletzt bearbeitet 18.09.2026 14:45:25
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat fold...
CVE-2026-70493
- EPSS 0.31%
- Veröffentlicht 04.08.2026 20:56:20
- Zuletzt bearbeitet 18.09.2026 14:45:36
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participa...