CVE-2026-45301
- EPSS 0.27%
- Veröffentlicht 15.05.2026 21:19:46
- Zuletzt bearbeitet 18.05.2026 20:16:38
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uplo...
CVE-2026-45345
- EPSS 0.23%
- Veröffentlicht 15.05.2026 21:17:27
- Zuletzt bearbeitet 18.05.2026 19:32:29
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's model even if its visibility is set to Private. By changing the access permissions during editing, una...
CVE-2026-45346
- EPSS 0.17%
- Veröffentlicht 15.05.2026 21:15:08
- Zuletzt bearbeitet 18.05.2026 19:31:41
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31.
CVE-2026-45347
- EPSS 0.19%
- Veröffentlicht 15.05.2026 21:12:30
- Zuletzt bearbeitet 18.05.2026 19:30:21
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF) via the PDF generate function. In the PDF export, user inputs are interpreted as H...
CVE-2026-45351
- EPSS 0.28%
- Veröffentlicht 15.05.2026 21:09:41
- Zuletzt bearbeitet 18.05.2026 20:16:39
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and...
CVE-2026-45666
- EPSS 0.28%
- Veröffentlicht 15.05.2026 21:07:42
- Zuletzt bearbeitet 19.05.2026 01:28:14
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging t...
CVE-2026-45365
- EPSS 0.19%
- Veröffentlicht 15.05.2026 21:07:12
- Zuletzt bearbeitet 19.05.2026 14:16:46
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI qu...
CVE-2026-44570
- EPSS 0.29%
- Veröffentlicht 15.05.2026 21:05:17
- Zuletzt bearbeitet 18.05.2026 19:52:38
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore,...
CVE-2026-44569
- EPSS 0.27%
- Veröffentlicht 15.05.2026 21:03:28
- Zuletzt bearbeitet 19.05.2026 16:38:23
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, there's an IDOR in the channels message management system that allows authenticated users to modify or delete any message within chann...
CVE-2026-44566
- EPSS 0.34%
- Veröffentlicht 15.05.2026 21:01:32
- Zuletzt bearbeitet 19.05.2026 20:12:16
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validated or saniti...