Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 04.08.2026 20:16:55
  • Zuletzt bearbeitet 18.09.2026 14:46:45

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 addres...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 04.08.2026 20:16:55
  • Zuletzt bearbeitet 18.09.2026 14:46:56

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files served from th...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 18.09.2026 14:45:45

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 04.08.2026 20:16:54
  • Zuletzt bearbeitet 18.09.2026 14:45:55

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser without a restricte...

  • EPSS 0.25%
  • Veröffentlicht 04.08.2026 20:16:11
  • Zuletzt bearbeitet 18.09.2026 14:57:56

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read access. Any au...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 15.07.2026 11:25:31
  • Zuletzt bearbeitet 16.07.2026 20:03:11

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui ins...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 15.07.2026 11:25:30
  • Zuletzt bearbeitet 16.07.2026 20:03:37

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the prof...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 17:43:06

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objects for channel members, including settings.ui.toolServers[].key and web...

  • EPSS 0.22%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 17:39:40

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_LIST matching compared configured host entries against URL strings and non-label-boundary suffixes, allowing path-based blocklist ...

  • EPSS 0.29%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 15:22:04

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL from an unencoded session_id and appended user_id as a query parameter, ...