Openwebui

Open Webui

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 15.05.2026 19:21:26
  • Zuletzt bearbeitet 19.05.2026 03:07:48

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from /api/v1/messages, re...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 15.05.2026 19:20:37
  • Zuletzt bearbeitet 19.05.2026 14:16:45

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API endpoint: /api/chat/completions with their own API key (generated in OWUI) and the Chat ID of another ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.05.2026 19:18:06
  • Zuletzt bearbeitet 19.05.2026 03:08:17

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks across the system and stop tasks belonging to other us...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.05.2026 19:13:42
  • Zuletzt bearbeitet 19.05.2026 03:08:53

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE /api/v1/files/{id} when the target file is referenc...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 15.05.2026 19:12:57
  • Zuletzt bearbeitet 19.05.2026 14:16:46

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regul...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 14.04.2026 01:39:07
  • Zuletzt bearbeitet 21.04.2026 23:31:23

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allows editing an image via a prompt. The affected funct...

Exploit
  • EPSS 5.27%
  • Veröffentlicht 01.04.2026 17:02:21
  • Zuletzt bearbeitet 15.04.2026 15:25:35

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 26.03.2026 23:54:38
  • Zuletzt bearbeitet 01.04.2026 16:09:53

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can read other users' private memories via `/api/v1/retrieval/query/collection`. Version 0.8.6 patches t...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 26.03.2026 23:39:33
  • Zuletzt bearbeitet 01.04.2026 16:10:43

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, an access control check is missing when deleting a file from a knowledge base. The only check being done is that the user has w...

Exploit
  • EPSS 2.86%
  • Veröffentlicht 26.03.2026 23:38:20
  • Zuletzt bearbeitet 01.04.2026 16:12:25

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the `POST /api/v1/retrieval/process/files/batch` endpoint...