CVE-2026-45338
- EPSS 0.4%
- Veröffentlicht 15.05.2026 21:46:32
- Zuletzt bearbeitet 18.05.2026 19:33:34
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). ...
CVE-2026-44549
- EPSS 0.32%
- Veröffentlicht 15.05.2026 21:45:16
- Zuletzt bearbeitet 19.05.2026 16:38:53
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the sheetjs function sheet_to_h...
CVE-2026-45299
- EPSS 0.2%
- Veröffentlicht 15.05.2026 21:44:17
- Zuletzt bearbeitet 18.05.2026 19:50:48
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the user profile update form accepted arbitrary data: URI values without MIME-type validation, resulting...
CVE-2026-45665
- EPSS 0.34%
- Veröffentlicht 15.05.2026 21:42:34
- Zuletzt bearbeitet 19.05.2026 01:28:01
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, D...
CVE-2026-45667
- EPSS 0.34%
- Veröffentlicht 15.05.2026 21:41:43
- Zuletzt bearbeitet 19.05.2026 01:28:24
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.app.state.EMBEDDING_FUNCTION(...). This allows any un...
CVE-2026-44565
- EPSS 0.45%
- Veröffentlicht 15.05.2026 21:40:50
- Zuletzt bearbeitet 19.05.2026 16:38:33
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTTP upload request and is not validated or sanitized....
CVE-2026-45314
- EPSS 0.22%
- Veröffentlicht 15.05.2026 21:31:24
- Zuletzt bearbeitet 18.05.2026 20:16:39
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the channel webhook create/update flow accepts arbitrary profile_image_url values, including data:image/svg+xml;base64,... payloads. Th...
CVE-2026-45316
- EPSS 0.22%
- Veröffentlicht 15.05.2026 21:30:36
- Zuletzt bearbeitet 18.05.2026 20:12:01
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the POST /api/v1/notes/{id}/pin endpoint performs a write operation (toggling the is_pinned field) but only checks for read permission....
CVE-2026-45317
- EPSS 0.17%
- Veröffentlicht 15.05.2026 21:29:44
- Zuletzt bearbeitet 18.05.2026 20:12:20
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, an application-wide Cross-Site Request Forgery (CSRF) vulnerability was found Open-WebUl's image uploading functionality. An attacker c...
CVE-2026-45318
- EPSS 0.21%
- Veröffentlicht 15.05.2026 21:28:57
- Zuletzt bearbeitet 18.05.2026 20:12:44
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, his advisory tracks a regression of the original Excel-preview XSS (CVE-2026-44549). The same root cause — XLSX.utils.sheet_to_html() o...