PatchSiren

open-webui CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM open-webui CVE published 2026-09-10

CVE-2026-88006

Open WebUI, a self-hosted AI platform, had a vulnerability in its OAuth token exchange endpoint from version 0.8.0 to 0.11.1. This endpoint would issue a session for a provider access token without properly running OAuth role management, unlike the normal OAuth login callback. Consequently, a user whose provider roles the login callback would refuse or demote could still obtain a working session at their [truncated]

MEDIUM open-webui CVE published 2026-09-10

CVE-2026-88005

CVE-2026-88005 is a vulnerability in Open WebUI, an extensible, feature-rich, and user-friendly self-hosted AI platform. From version 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. This issue allows an account whose email domain the login callback would ref [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-88002

An authenticated user could store id-less messages in a parent cycle and trigger a non-terminating walk that blocked the async event loop, grew memory until termination, and remained persistent across process restarts in Open WebUI versions 0.5.0 through 0.11.1. This issue is fixed in version 0.11.1. The vulnerability allows an authenticated user to cause a denial-of-service condition, impacting the avail [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-88001

CVE-2026-88001 is a vulnerability in Open WebUI, a self-hosted AI platform, that allows an authenticated user to redirect server-side web fetches to excluded hosts, loopback, private networks, or cloud metadata services. This issue, fixed in version 0.11.1, could potentially route resulting content into web search, URL ingestion, page-fetch tools, or chat image processing.

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-88000

CVE-2026-88000 is a vulnerability in Open WebUI, a self-hosted AI platform, that could lead to a denial-of-service (DoS) condition. An authenticated user could exploit this vulnerability by storing a cyclic chat tree and deleting a message, causing a synchronous infinite loop on the server request loop that blocked every user's requests until the process was killed. The issue is fixed in version 0.11.1.

HIGH open-webui CVE published 2026-09-09

CVE-2026-87999

Open WebUI, an AI platform, had a vulnerability prior to version 0.11.1 that allowed an authenticated user to make the instance fetch and return content from reserved IP ranges, such as 168.63.129.16, used by Azure. This issue is now fixed. The vulnerability was due to incorrect classification of Python's globally routable addresses, which led to potential unauthorized access and disruption of services. D [truncated]

HIGH open-webui CVE published 2026-09-09

CVE-2026-87998

A vulnerability in Open WebUI, a self-hosted AI platform, allows a non-administrator with write access to delete shared instance configurations, potentially making other knowledge bases using the same connection unavailable. This issue, fixed in version 0.11.1, has a CVSS score of 7.1 and is considered high severity. The vulnerability exists due to insufficient checks in the DELETE /api/v1/knowledge/{id}/ [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87997

CVE-2026-87997 is a vulnerability in Open WebUI, a self-hosted AI platform, where an authenticated user could inject an attacker-controlled chat into a folder where the user had read-only or no write access. This issue allows potential unauthorized chat injections into folders without proper write access checks, affecting folder readers. The vulnerability exists in Open WebUI versions from 0.10.0 until 0. [truncated]

HIGH open-webui CVE published 2026-09-09

CVE-2026-87996

Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.9.6 to 0.11.1 that allowed an authenticated user to potentially expose internal services or cloud metadata by manipulating DNS responses. This issue is fixed in version 0.11.1. The vulnerability was caused by the SafePlaywrightURLLoader not properly validating user-controlled hostnames, which could lead to DNS manipulation and exposu [truncated]

HIGH open-webui CVE published 2026-09-09

CVE-2026-87995

CVE-2026-87995 is a high-severity vulnerability in Open WebUI, a self-hosted AI platform. From version 0.8.11 to 0.11.1, the platform rendered terminal port content in an iframe sandbox with allow-scripts and allow-same-origin, allowing an authenticated user to host malicious scripts and potentially take over a victim's account when the victim opened the preview.

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87994

A vulnerability in Open WebUI, a self-hosted AI platform, allows a channel member to replace another member's message in a conversation record without gaining access to other channels. This issue, fixed in version 0.11.1, has a medium CVSS score of 4.3. The vulnerability exists in versions between 0.9.5 and 0.11.1, and defenders should assess exposure and verify conversation records for potential tamperin [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87017

CVE-2026-87017 is a vulnerability in Open WebUI, an extensible, feature-rich, and user-friendly self-hosted AI platform. From version 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the search methods in eleven shipped vector backends ignored that filter. An authenticated user on an affected backend could enumerate th [truncated]

HIGH open-webui CVE published 2026-09-09

CVE-2026-87016

Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.6.41 to 0.11.1. The get_user_by_oauth_sub and get_user_by_scim_external_id functions in users.py used JSON containing matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject with percent or underscore wildcard characters could resolve to a different stored identity, potentially selecting an administrator acc [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87015

Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.6.27 to 0.11.1 where session cookies could be improperly shared across tool servers, potentially allowing unauthorized account takeover. This issue is fixed in version 0.11.1. The vulnerability allowed an attacker to reuse session cookies across different tool servers configured for bearer authentication, which could lead to account [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87014

CVE-2026-87014 is a medium-severity vulnerability in Open WebUI, a self-hosted AI platform. From version 0.9.0 to 0.11.1, an issue with role synchronization could allow an administrator demoted through a trusted role header or OAuth role mapping to retain access to collaborative notes via an open Socket.IO connection. This issue arises because the role update does not invalidate the cached user record. De [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87013

An authenticated user could exploit this vulnerability in Open WebUI versions from 0.10.0 to 0.11.0 to cause a denial of service by creating a cycle in the folder tree structure, potentially leading to resource exhaustion and data access disruption. This issue is fixed in version 0.11.1. The vulnerability allows an attacker to create a cycle in the folder tree structure, which can be used to cause a denia [truncated]

MEDIUM open-webui CVE published 2026-09-09

CVE-2026-87012

CVE-2026-87012 is a vulnerability in Open WebUI, a self-hosted AI platform, affecting versions from 0.9.0 to 0.11.1. An authenticated user with calendar permissions could store a non-numeric value for alert_minutes, causing an exception that aborted the instance-wide alert pass and suppressed reminders for all users. This issue is fixed in version 0.11.1.

HIGH open-webui CVE published 2026-09-09

CVE-2026-87011

CVE-2026-87011 is a high-severity vulnerability in Open WebUI, a self-hosted AI platform. The issue, fixed in version 0.11.1, involves an unauthenticated POST handler that can stall the single-worker instance and amplify traffic to the identity provider. This could impact instance availability and potentially lead to increased load on the identity provider. Defenders responsible for Open WebUI instances, [truncated]

HIGH open-webui CVE published 2026-08-13

CVE-2026-59714

Open WebUI, a self-hosted AI platform, has a vulnerability allowing authenticated users to overwrite message content in channels they do not belong to, including private and DM channels, by sending a specially crafted chat completion request. This issue, fixed in version 0.10.0, has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability exists because the _make_channel_emitter pipeline wri [truncated]

HIGH open-webui CVE published 2026-08-04

CVE-2026-70494

A vulnerability in Open WebUI, a self-hosted AI platform, allowed users with write access to a shared chat folder to delete chats and messages belonging to the folder owner. This issue, fixed in version 0.11.0, highlights the importance of proper authorization checks in collaborative environments. The vulnerability was caused by a flawed authorization check that accepted any inherited write grant instead [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70493

Open WebUI, a self-hosted AI platform, has a vulnerability in versions 0.9.6 to 0.10.0 that allows a crafted regex pattern to cause a denial-of-service (DoS) attack. This DoS attack can impact availability for other users of the affected worker. The vulnerability arises from the built-in knowledge search path in Open WebUI, which enables a chat participant to choose a pattern used to grep knowledge files. [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70491

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T21:16:38.050Z and has not been modified since then. Open WebUI, an extensible and feature-rich self-hosted AI platform, has a vulnerability in versions 0.10.2 and earlier. Authenticated non-admin users can obtain full Python tool source via certain API endpoints, potentially exposing hard-coded c [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70490

CVE-2026-70490 is a vulnerability in Open WebUI, an extensible, feature-rich, and user-friendly self-hosted AI platform. From version 0.8.8 until 0.11.0, the terminal WebSocket route did not properly authenticate and authorize users, allowing accounts with pending roles, including registered but unapproved accounts or deactivated accounts, to open interactive terminal sessions when at least one terminal s [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70489

Open WebUI, a self-hosted AI platform, had a vulnerability in versions 0.9.0 to 0.10.0 where automation recurrence parsing could cause significant availability impact. The issue, fixed in version 0.11.0, involved inefficient computation of recurring events that could block the event loop used for scheduler, HTTP, and WebSocket traffic. This could lead to performance degradation and potential downtime for [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70488

A vulnerability in Open WebUI, a self-hosted AI platform, allows users with write access to one knowledge base to delete directories and remove file embeddings from another knowledge base. This issue, fixed in version 0.11.0, could cause documents to drop out of retrieval results and break chat-with-file functionality for targeted documents. The vulnerability arises from the sync cleanup endpoint's lack o [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70487

CVE-2026-70487 debrief based on CVE Program and NVD records. Open WebUI 0.8.8 to 0.10.0 allows read-only cross-user confidentiality loss via knowledge attachments. Fixed in 0.11.0. The vulnerability allows authenticated users to access knowledge attachments from other users, potentially leading to read-only cross-user confidentiality loss. Open WebUI administrators and security teams should assess exposur [truncated]

HIGH open-webui CVE published 2026-08-04

CVE-2026-70486

Open WebUI, a self-hosted AI platform, had a vulnerability from version 0.9.0 to 0.11.0 that allowed an authenticated user with terminal server access to execute scripts in previewed HTML files, potentially leading to account takeover and server-side code execution. The issue is fixed in version 0.11.0. This vulnerability was particularly concerning because it could be exploited by any authenticated user [truncated]

HIGH open-webui CVE published 2026-08-04

CVE-2026-70485

Open WebUI, a self-hosted AI platform, had a vulnerability from version 0.9.0 to 0.11.0 where it failed to properly check if a user-supplied URL was globally routable, specifically with IPv6 addresses and embedded IPv4 addresses in transition encodings. This allowed verified users to access internal or cloud-metadata IPv4 addresses via NAT64 gateways, potentially leading to unauthorized information disclo [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70484

An authenticated user with revoked image-generation permissions could still use chat completions to consume the operator's image provider, spending API credits and quota, and writing generated files to storage. This issue arises from the legacy chat-completions feature in Open WebUI from version 0.7.0 to 0.10.0 not properly checking the image_generation permission. Defenders should assess exposure and pri [truncated]

LOW open-webui CVE published 2026-08-04

CVE-2026-70483

Open WebUI, a self-hosted AI platform, had a vulnerability from version 0.9.6 to 0.11.0 where an authenticated user could abort another user's running model response, title generation, or tag generation by sending a DELETE request to /api/v1/chats/{id}, even though the delete operation was refused and no chat data was deleted, modified, or disclosed. This issue was fixed in version 0.11.0.