Openwebui

Open Webui

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 15.05.2026 20:59:17
  • Zuletzt bearbeitet 19.05.2026 16:38:15

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of user. By default, when Open WebUI is configured with ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 15.05.2026 20:55:00
  • Zuletzt bearbeitet 19.05.2026 16:39:01

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 15.05.2026 20:40:47
  • Zuletzt bearbeitet 19.05.2026 12:08:07

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability. This vulnerability is fixed in 0....

Exploit
  • EPSS 0.35%
  • Veröffentlicht 15.05.2026 20:40:04
  • Zuletzt bearbeitet 18.05.2026 19:53:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file to a resource the caller controls (folder knowledge, k...

Medienbericht Exploit
  • EPSS 0.3%
  • Veröffentlicht 15.05.2026 20:37:29
  • Zuletzt bearbeitet 19.05.2026 12:07:26

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only validates the initial URL submitted by the caller. The HT...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 15.05.2026 20:36:21
  • Zuletzt bearbeitet 19.05.2026 14:16:46

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, Pin/Unpin is a write operation (modifies the message's is_pinned , pinned_by, pinned_at fields), but in standard channels it only check...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 15.05.2026 20:35:35
  • Zuletzt bearbeitet 19.05.2026 12:18:19

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name prefixes but does not check knowledge base collection...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 15.05.2026 20:34:23
  • Zuletzt bearbeitet 19.05.2026 12:19:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 20:33:47
  • Zuletzt bearbeitet 19.05.2026 12:20:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 15.05.2026 20:33:02
  • Zuletzt bearbeitet 19.05.2026 03:05:29

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspace.tools permission check that is present on the too...