Openwebui

Open Webui

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 15.05.2026 21:41:43
  • Zuletzt bearbeitet 19.05.2026 01:28:24

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.app.state.EMBEDDING_FUNCTION(...). This allows any un...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 15.05.2026 21:40:50
  • Zuletzt bearbeitet 19.05.2026 16:38:33

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTTP upload request and is not validated or sanitized....

Exploit
  • EPSS 0.21%
  • Veröffentlicht 15.05.2026 21:31:24
  • Zuletzt bearbeitet 18.05.2026 20:16:39

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the channel webhook create/update flow accepts arbitrary profile_image_url values, including data:image/svg+xml;base64,... payloads. Th...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 15.05.2026 21:30:36
  • Zuletzt bearbeitet 18.05.2026 20:12:01

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the POST /api/v1/notes/{id}/pin endpoint performs a write operation (toggling the is_pinned field) but only checks for read permission....

Exploit
  • EPSS 0.17%
  • Veröffentlicht 15.05.2026 21:29:44
  • Zuletzt bearbeitet 18.05.2026 20:12:20

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, an application-wide Cross-Site Request Forgery (CSRF) vulnerability was found Open-WebUl's image uploading functionality. An attacker c...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 15.05.2026 21:28:57
  • Zuletzt bearbeitet 18.05.2026 20:12:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, his advisory tracks a regression of the original Excel-preview XSS (CVE-2026-44549). The same root cause — XLSX.utils.sheet_to_html() o...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 15.05.2026 21:26:54
  • Zuletzt bearbeitet 19.05.2026 18:16:21

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/aud...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 15.05.2026 21:24:52
  • Zuletzt bearbeitet 18.05.2026 19:51:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, in standard channels (i.e., channels whose channel.type is neither group nor dm), the endpoint POST /api/v1/channels/{channel_id}/messa...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 15.05.2026 21:23:49
  • Zuletzt bearbeitet 18.05.2026 19:27:38

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, there is a vulnerability in chat completion API, which allows attackers to bypass tool restrictions, potentially enabling unauthorized ...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 15.05.2026 21:21:43
  • Zuletzt bearbeitet 19.05.2026 14:16:45

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend provides a function to visualize the HTML content o...