- EPSS 0.31%
- Veröffentlicht 09.07.2026 17:17:02
- Zuletzt bearbeitet 13.07.2026 12:24:30
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was ...
CVE-2026-59217
- EPSS 0.29%
- Veröffentlicht 09.07.2026 17:17:02
- Zuletzt bearbeitet 14.07.2026 02:16:57
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write-access che...
CVE-2026-59219
- EPSS 0.31%
- Veröffentlicht 09.07.2026 17:17:02
- Zuletzt bearbeitet 10.07.2026 18:17:21
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used...
CVE-2026-59212
- EPSS 0.33%
- Veröffentlicht 09.07.2026 17:17:01
- Zuletzt bearbeitet 10.07.2026 19:59:36
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file write and delete routes later trusted object-derived access through writ...
CVE-2026-59221
- EPSS 0.36%
- Veröffentlicht 09.07.2026 17:13:36
- Zuletzt bearbeitet 10.07.2026 02:37:15
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times percent-encode...
CVE-2026-59715
- EPSS 0.22%
- Veröffentlicht 09.07.2026 16:16:02
- Zuletzt bearbeitet 10.07.2026 02:41:47
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and ydoc:document:leave Socket.IO handlers accepte...
CVE-2026-59220
- EPSS 0.37%
- Veröffentlicht 09.07.2026 16:09:41
- Zuletzt bearbeitet 10.07.2026 18:15:48
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions wit...
CVE-2026-59226
- EPSS 0.3%
- Veröffentlicht 09.07.2026 16:06:55
- Zuletzt bearbeitet 10.07.2026 02:42:18
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and chec...
CVE-2026-59227
- EPSS 0.26%
- Veröffentlicht 09.07.2026 15:56:44
- Zuletzt bearbeitet 14.07.2026 02:16:57
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user image-generati...
CVE-2026-59218
- EPSS 0.24%
- Veröffentlicht 09.07.2026 15:53:54
- Zuletzt bearbeitet 10.07.2026 18:30:58
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-a...