CVE-2026-54016
- EPSS 0.23%
- Veröffentlicht 23.06.2026 16:43:13
- Zuletzt bearbeitet 25.06.2026 14:31:06
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native functio...
CVE-2026-54018
- EPSS 0.29%
- Veröffentlicht 23.06.2026 16:42:00
- Zuletzt bearbeitet 25.06.2026 14:30:18
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attacks by checking the IP address of the user-provided ...
CVE-2026-54019
- EPSS 0.28%
- Veröffentlicht 23.06.2026 16:41:18
- Zuletzt bearbeitet 25.06.2026 14:27:13
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. The ACL all...
CVE-2026-54021
- EPSS 0.21%
- Veröffentlicht 23.06.2026 16:39:58
- Zuletzt bearbeitet 25.06.2026 14:23:23
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a caller-supplied url_idx path parameter and use it as a raw index into the ...
CVE-2026-54022
- EPSS 0.27%
- Veröffentlicht 23.06.2026 16:38:13
- Zuletzt bearbeitet 25.06.2026 14:12:50
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocM...
CVE-2026-54017
- EPSS 0.35%
- Veröffentlicht 18.06.2026 21:09:07
- Zuletzt bearbeitet 24.06.2026 19:04:33
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segmen...
CVE-2026-45338
- EPSS 0.38%
- Veröffentlicht 15.05.2026 21:46:32
- Zuletzt bearbeitet 18.05.2026 19:33:34
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). ...
CVE-2026-44549
- EPSS 0.32%
- Veröffentlicht 15.05.2026 21:45:16
- Zuletzt bearbeitet 19.05.2026 16:38:53
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the sheetjs function sheet_to_h...
CVE-2026-45299
- EPSS 0.2%
- Veröffentlicht 15.05.2026 21:44:17
- Zuletzt bearbeitet 18.05.2026 19:50:48
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the user profile update form accepted arbitrary data: URI values without MIME-type validation, resulting...
CVE-2026-45665
- EPSS 0.32%
- Veröffentlicht 15.05.2026 21:42:34
- Zuletzt bearbeitet 19.05.2026 01:28:01
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, D...