CVE-2026-59226
- EPSS 0.3%
- Veröffentlicht 09.07.2026 16:06:55
- Zuletzt bearbeitet 10.07.2026 02:42:18
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and chec...
CVE-2026-59227
- EPSS 0.26%
- Veröffentlicht 09.07.2026 15:56:44
- Zuletzt bearbeitet 14.07.2026 02:16:57
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did not enforce the global image-edit switch or the per-user image-generati...
CVE-2026-59218
- EPSS 0.24%
- Veröffentlicht 09.07.2026 15:53:54
- Zuletzt bearbeitet 10.07.2026 18:30:58
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcrypt password verification when a credential existed, making registered-a...
- EPSS 0.29%
- Veröffentlicht 09.07.2026 15:51:38
- Zuletzt bearbeitet 10.07.2026 19:24:29
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js ...
CVE-2026-54007
- EPSS 0.18%
- Veröffentlicht 23.06.2026 16:51:27
- Zuletzt bearbeitet 26.06.2026 20:17:25
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the chat message listener allows non-same-origin input:prompt and action:submit messages, so an external site can set prompt text and t...
CVE-2026-54006
- EPSS 0.21%
- Veröffentlicht 23.06.2026 16:50:44
- Zuletzt bearbeitet 25.06.2026 13:41:57
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/v1/calendars/events/{event_id}/update validates that the caller has write access to the calendar the event currently belongs ...
CVE-2026-54008
- EPSS 0.23%
- Veröffentlicht 23.06.2026 16:50:06
- Zuletzt bearbeitet 25.06.2026 13:35:46
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.C...
CVE-2026-54009
- EPSS 0.27%
- Veröffentlicht 23.06.2026 16:49:13
- Zuletzt bearbeitet 25.06.2026 13:35:03
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url value that, when it does NOT start with http://, https://, or data:image/, is inter...
CVE-2026-54010
- EPSS 0.29%
- Veröffentlicht 23.06.2026 16:48:22
- Zuletzt bearbeitet 25.06.2026 13:34:24
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or ca...
CVE-2026-54011
- EPSS 0.23%
- Veröffentlicht 23.06.2026 16:47:43
- Zuletzt bearbeitet 25.06.2026 13:33:32
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using innerHT...