CVE-2026-45315
- EPSS 0.19%
- Veröffentlicht 15.05.2026 21:26:54
- Zuletzt bearbeitet 19.05.2026 18:16:21
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/aud...
CVE-2026-44571
- EPSS 0.28%
- Veröffentlicht 15.05.2026 21:24:52
- Zuletzt bearbeitet 18.05.2026 19:51:44
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, in standard channels (i.e., channels whose channel.type is neither group nor dm), the endpoint POST /api/v1/channels/{channel_id}/messa...
CVE-2026-45350
- EPSS 0.27%
- Veröffentlicht 15.05.2026 21:23:49
- Zuletzt bearbeitet 18.05.2026 19:27:38
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, there is a vulnerability in chat completion API, which allows attackers to bypass tool restrictions, potentially enabling unauthorized ...
CVE-2026-45303
- EPSS 0.23%
- Veröffentlicht 15.05.2026 21:21:43
- Zuletzt bearbeitet 19.05.2026 14:16:45
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend provides a function to visualize the HTML content o...
CVE-2026-45301
- EPSS 0.27%
- Veröffentlicht 15.05.2026 21:19:46
- Zuletzt bearbeitet 18.05.2026 20:16:38
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uplo...
CVE-2026-45345
- EPSS 0.23%
- Veröffentlicht 15.05.2026 21:17:27
- Zuletzt bearbeitet 18.05.2026 19:32:29
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's model even if its visibility is set to Private. By changing the access permissions during editing, una...
CVE-2026-45346
- EPSS 0.17%
- Veröffentlicht 15.05.2026 21:15:08
- Zuletzt bearbeitet 18.05.2026 19:31:41
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.31, there is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation. This vulnerability is fixed in 0.6.31.
CVE-2026-45347
- EPSS 0.19%
- Veröffentlicht 15.05.2026 21:12:30
- Zuletzt bearbeitet 18.05.2026 19:30:21
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF) via the PDF generate function. In the PDF export, user inputs are interpreted as H...
CVE-2026-45351
- EPSS 0.28%
- Veröffentlicht 15.05.2026 21:09:41
- Zuletzt bearbeitet 18.05.2026 20:16:39
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and...
CVE-2026-45666
- EPSS 0.28%
- Veröffentlicht 15.05.2026 21:07:42
- Zuletzt bearbeitet 19.05.2026 01:28:14
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging t...