Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 21:24:55
  • Zuletzt bearbeitet 16.09.2026 15:15:32

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a supplied mess...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 09.09.2026 21:23:27
  • Zuletzt bearbeitet 16.09.2026 15:23:05

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 09.09.2026 21:21:43
  • Zuletzt bearbeitet 15.09.2026 15:29:13

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.09.2026 21:17:06
  • Zuletzt bearbeitet 15.09.2026 16:09:34

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the folder tree wal...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 09.09.2026 21:17:06
  • Zuletzt bearbeitet 15.09.2026 15:56:08

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 09.09.2026 21:17:06
  • Zuletzt bearbeitet 15.09.2026 15:54:14

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each external tool cal...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.09.2026 20:57:58
  • Zuletzt bearbeitet 15.09.2026 16:17:55

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-ev...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 09.09.2026 20:54:26
  • Zuletzt bearbeitet 15.09.2026 16:26:18

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and sig...

  • EPSS 0.3%
  • Veröffentlicht 04.08.2026 20:58:05
  • Zuletzt bearbeitet 18.09.2026 14:45:25

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat fold...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 04.08.2026 20:56:20
  • Zuletzt bearbeitet 18.09.2026 14:45:36

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participa...