Openwebui

Open Webui

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 15.05.2026 20:32:02
  • Zuletzt bearbeitet 19.05.2026 03:05:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, when setting model permissions so that a group has read access to it, intending for other users to use it, those users also can read th...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 15.05.2026 20:29:36
  • Zuletzt bearbeitet 19.05.2026 01:45:35

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, an IDOR vulnerability exists in the Channels feature of Open WebUI, allowing any channel member to modify messages sent by other member...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 20:02:16
  • Zuletzt bearbeitet 19.05.2026 14:16:45

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a stored cross-site scripting (XSS) vulnerability that allows any authenticated user with model creation permission (workspace.models) ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 15.05.2026 20:00:59
  • Zuletzt bearbeitet 19.05.2026 03:12:01

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fields to pass through Pydantic validation and be inc...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 15.05.2026 19:59:35
  • Zuletzt bearbeitet 18.05.2026 18:35:23

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is non-empty before performing a Simple Bind against the...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 19:57:22
  • Zuletzt bearbeitet 18.05.2026 18:32:33

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis datab...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 15.05.2026 19:54:09
  • Zuletzt bearbeitet 19.05.2026 14:16:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to disconnect affected sessions. As a result, a user whose a...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 15.05.2026 19:49:55
  • Zuletzt bearbeitet 19.05.2026 03:12:09

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_name and an overwrite query parameter (default: True...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 15.05.2026 19:48:35
  • Zuletzt bearbeitet 19.05.2026 03:12:26

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composition via base_model_id: a user-defined model (e.g., "Cheap Assistant") can reference an existing base ...

  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 19:46:17
  • Zuletzt bearbeitet 19.05.2026 03:12:44

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers wi...