Openwebui

Open Webui

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 09.07.2026 15:51:38
  • Zuletzt bearbeitet 10.07.2026 19:24:29

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js ...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 23.06.2026 16:51:27
  • Zuletzt bearbeitet 26.06.2026 20:17:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the chat message listener allows non-same-origin input:prompt and action:submit messages, so an external site can set prompt text and t...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 16:50:44
  • Zuletzt bearbeitet 25.06.2026 13:41:57

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/v1/calendars/events/{event_id}/update validates that the caller has write access to the calendar the event currently belongs ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.06.2026 16:50:06
  • Zuletzt bearbeitet 25.06.2026 13:35:46

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.C...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.06.2026 16:49:13
  • Zuletzt bearbeitet 25.06.2026 13:35:03

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url value that, when it does NOT start with http://, https://, or data:image/, is inter...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 16:48:22
  • Zuletzt bearbeitet 25.06.2026 13:34:24

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or ca...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.06.2026 16:47:43
  • Zuletzt bearbeitet 25.06.2026 13:33:32

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using innerHT...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 16:47:03
  • Zuletzt bearbeitet 25.06.2026 13:26:51

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their model without...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 16:46:28
  • Zuletzt bearbeitet 26.06.2026 20:17:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 16:45:39
  • Zuletzt bearbeitet 25.06.2026 14:36:17

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a path traversal vulnerability exists in open-webui's cache file serving endpoint that allows any authenticated user to read files from...