Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 09.07.2026 17:17:03
  • Zuletzt bearbeitet 10.07.2026 02:44:19

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 10.07.2026 19:49:23

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permis...

  • EPSS 0.26%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 13.07.2026 12:27:12

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message fr...

  • EPSS 0.31%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 13.07.2026 12:24:30

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 14.07.2026 02:16:57

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write-access che...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.07.2026 17:17:02
  • Zuletzt bearbeitet 10.07.2026 18:17:21

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 09.07.2026 17:17:01
  • Zuletzt bearbeitet 10.07.2026 19:59:36

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file write and delete routes later trusted object-derived access through writ...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 09.07.2026 17:13:36
  • Zuletzt bearbeitet 10.07.2026 02:37:15

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times percent-encode...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 09.07.2026 16:16:02
  • Zuletzt bearbeitet 10.07.2026 02:41:47

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and ydoc:document:leave Socket.IO handlers accepte...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 09.07.2026 16:09:41
  • Zuletzt bearbeitet 10.07.2026 18:15:48

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions wit...