Openwebui

Open Webui

175 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 23.06.2026 16:47:03
  • Zuletzt bearbeitet 25.06.2026 13:26:51

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their model without...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 16:46:28
  • Zuletzt bearbeitet 26.06.2026 20:17:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 16:45:39
  • Zuletzt bearbeitet 25.06.2026 14:36:17

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a path traversal vulnerability exists in open-webui's cache file serving endpoint that allows any authenticated user to read files from...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 16:44:57
  • Zuletzt bearbeitet 25.06.2026 14:35:30

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-history endpoints authorize the prompt_id in the URL but then act on caller-supplied history IDs without ve...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 23.06.2026 16:43:13
  • Zuletzt bearbeitet 25.06.2026 14:31:06

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin search_knowledge_files tool. When native functio...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.06.2026 16:42:00
  • Zuletzt bearbeitet 25.06.2026 14:30:18

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attacks by checking the IP address of the user-provided ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.06.2026 16:41:18
  • Zuletzt bearbeitet 25.06.2026 14:27:13

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. The ACL all...

  • EPSS 0.21%
  • Veröffentlicht 23.06.2026 16:39:58
  • Zuletzt bearbeitet 26.06.2026 20:17:26

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a caller-supplied url_idx path parameter and use it as a raw index into the ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 16:38:13
  • Zuletzt bearbeitet 25.06.2026 14:12:50

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocM...

  • EPSS 0.52%
  • Veröffentlicht 18.06.2026 21:09:07
  • Zuletzt bearbeitet 24.06.2026 19:04:33

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segmen...