PatchSiren

open-webui CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70481

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:55.050Z and has not been modified since then. Open WebUI, an extensible and feature-rich self-hosted AI platform, had a vulnerability affecting standard channel message update and delete handlers from version 0.5.0 until 0.11.0. This issue allowed any participant with write access to rewrit [truncated]

MEDIUM open-webui CVE published 2026-08-04

CVE-2026-70480

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:54.903Z and has not been modified since then. Open WebUI, an extensible and feature-rich self-hosted AI platform, is vulnerable to a security issue. From version 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the view [truncated]

HIGH open-webui CVE published 2026-08-04

CVE-2026-70479

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T20:16:54.760Z and has not been modified since then. Open WebUI, an extensible and feature-rich self-hosted AI platform, has a vulnerability in versions from 0.9.6 until 0.11.0. This vulnerability allows an authenticated user to potentially access blocked internal addresses using JavaScript and in [truncated]

HIGH open-webui CVE published 2026-07-15

CVE-2026-56398

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow. The picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be stored as data URIs. Authenticated users who visit the profile image endpoint receive attacker-controlled SVG content with inline dispos [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59227

Open WebUI, an extensible and feature-rich self-hosted AI platform, had a vulnerability in versions from 0.8.11 up to but not including 0.10.0. The issue allowed a non-admin user to invoke server-side image editing with administrator-configured provider credentials via the POST /api/v1/images/edit endpoint. This was possible because the endpoint required only a verified account and did not enforce the glo [truncated]

HIGH open-webui CVE published 2026-07-09

CVE-2026-59224

Open WebUI, a self-hosted AI platform, had a vulnerability prior to version 0.10.0. The issue was in the `terminals.py` file, where the `ws_terminal` upstream URL was built from an unencoded `session_id` and had `user_id` appended as a query parameter. This allowed for query injection, enabling the terminal backend to resolve another user's identity. The HTTP proxy path also forwarded `X-User-Id` as an in [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59223

Open WebUI, a self-hosted AI platform, is vulnerable to a blocklist bypass issue due to improper comparison of configured host entries against URL strings and non-label-boundary suffixes. This allows for path-based blocklist bypasses and sibling-domain matches that do not reflect the intended hostname policy. The issue is fixed in version 0.10.0. Users of Open WebUI, especially those hosting it, should be [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59222

CVE-2026-59222 is a sensitive information disclosure vulnerability in Open WebUI, a self-hosted AI platform. Versions from 0.7.0 to before 0.10.0 are affected. An authenticated user could exploit this vulnerability to obtain sensitive information about other users. The vulnerability exists in the GET /api/v1/channels//members endpoint, which returns full UserModelResponse objects for channel members, incl [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59220

CVE-2026-59220 is a MEDIUM severity vulnerability in Open WebUI, a self-hosted AI platform. From version 0.9.2 to before 0.10.0, the platform is susceptible to quadratic backtracking due to overlapping quantifiers in the SKILL_MENTION_RE and strip_re regular expressions. This issue allows an authenticated user to block the asyncio event loop by sending a chat message containing a malformed skill mention, [truncated]

HIGH open-webui CVE published 2026-07-09

CVE-2026-59219

Open WebUI, a self-hosted AI platform, had an authentication bypass issue. From version 0.9.0 to before 0.10.0, with Redis configured, the Socket.IO connection and certain websocket messages did not properly check for revoked JWTs, allowing continued authentication with revoked tokens. This issue was fixed in version 0.10.0. The affected product deployments should be reviewed, and owners should be assigne [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59218

CVE-2026-59218 is an account enumeration vulnerability in Open WebUI prior to version 0.10.0. This issue allows attackers to determine if an account exists by analyzing response times during the authentication process. The vulnerability is due to the /api/v1/auths/signin endpoint looking up users by email and only performing bcrypt password verification if a credential existed. This results in measurably [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59217

CVE-2026-59217 is a vulnerability in Open WebUI's file upload path. Prior to version 0.10.0, the file upload path accepted metadata and auto-linked uploaded files to a target knowledge base without applying the write-access check used by /api/v1/knowledge//file/add. This allowed read-only knowledge-base users to add arbitrary files. The issue is fixed in version 0.10.0. Affected product or component is Op [truncated]

HIGH open-webui CVE published 2026-07-09

CVE-2026-59216

CVE-2026-59216 is a high-severity vulnerability in Open WebUI, a self-hosted AI platform. The issue allows authenticated users to execute code in another user's session, potentially leading to unauthorized access and data breaches. The vulnerability was patched in version 0.10.0. Users of Open WebUI should prioritize upgrading to version 0.10.0 or later to mitigate this vulnerability. The vulnerability ex [truncated]

LOW open-webui CVE published 2026-07-09

CVE-2026-59215

CVE-2026-59215 is a low-severity vulnerability in Open WebUI, a self-hosted AI platform. Prior to version 0.10.0, the platform did not properly bind parent message IDs to specific channels in URLs, allowing authenticated users to access thread context from private or direct message channels they were not a part of. This issue has been fixed in Open WebUI version 0.10.0. Affected users, especially those ho [truncated]

HIGH open-webui CVE published 2026-07-09

CVE-2026-59214

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-09T17:17:02.177Z and has not been modified since then. The NVD entry is currently Analyzed. Open WebUI, a self-hosted AI platform, runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads to issue authenticated same-origin requests when a victim clicks Run. Thi [truncated]

LOW open-webui CVE published 2026-07-09

CVE-2026-59213

CVE-2026-59213 is a low-severity vulnerability in Open WebUI, a self-hosted AI platform. A cache issue in versions 0.6.27 to 0.9.9 allows permission-filtered per-user model lists to share a static cache entry, potentially exposing one user's model list to another caller during the TTL window. The issue is fixed in version 0.10.0. This vulnerability has a CVSS score of 3.5 and is considered low severity. U [truncated]

MEDIUM open-webui CVE published 2026-07-09

CVE-2026-59212

Open WebUI, an extensible and feature-rich self-hosted AI platform, had a security issue in versions 0.9.6 and prior. The _verify_knowledge_file_access function only checked read access, while file write and delete routes later trusted object-derived access through writable model meta.knowledge entries. This allowed a user with read-only knowledge file access to upgrade to file write or delete operations. [truncated]

MEDIUM open-webui CVE published 2026-06-23

CVE-2026-54022

CVE-2026-54022 is a vulnerability in Open WebUI, a self-hosted artificial intelligence platform. The issue allows an attacker to bypass authorization checks and access private note contents by manipulating document IDs. The vulnerability is fixed in version 0.8.11. Open WebUI is a platform designed to operate entirely offline. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.

MEDIUM open-webui CVE published 2026-06-23

CVE-2026-54021

CVE-2026-54021 is a vulnerability in Open WebUI, a self-hosted artificial intelligence platform. The vulnerability allows authenticated users to access unauthorized Ollama backends by manipulating the url_idx path parameter. This issue was fixed in version 0.9.6. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 6.3, indicating a medium severity level. The vulnerability was pu [truncated]

HIGH open-webui CVE published 2026-06-23

CVE-2026-54018

CVE-2026-54018 is a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI, a self-hosted artificial intelligence platform. The vulnerability arises from the platform's failure to validate URLs after HTTP redirects, allowing attackers to access internal services despite protective configurations. This issue was fixed in version 0.9.6. The vulnerability has a CVSS score of 7.7 and is considered hig [truncated]

MEDIUM open-webui CVE published 2026-06-23

CVE-2026-54014

CVE-2026-54014 is a path traversal vulnerability in Open WebUI's cache file serving endpoint. The vulnerability allows any authenticated user to read files from sibling directories outside the intended cache directory. This is achieved by exploiting an incomplete startswith containment check that lacks a trailing path separator. The root cause lies in the serve_cache_file() function in open_webui/main.py, [truncated]

HIGH open-webui CVE published 2026-06-23

CVE-2026-54013

Open WebUI, a self-hosted AI platform, had an SVG XSS vulnerability in model profile images prior to version 0.9.6. The ModelMeta class lacked a profile image URL validator, and the image serving endpoint had no MIME allowlist or nosniff header. Authenticated users with workspace.models permission could store malicious SVG images, leading to full account takeover when navigated to. The vulnerability was p [truncated]

HIGH open-webui CVE published 2026-06-23

CVE-2026-54011

CVE-2026-54011 is a high-severity vulnerability in Open WebUI, a self-hosted artificial intelligence platform. The vulnerability arises from the platform's rendering of Mermaid blocks from Markdown files in the file preview panel. Specifically, Open WebUI inserts the generated SVG into the DOM using innerHTML, and Mermaid is configured with securityLevel: 'loose'. This allows attacker-controlled Mermaid c [truncated]

HIGH open-webui CVE published 2026-06-23

CVE-2026-54007

CVE-2026-54007 is a high-severity vulnerability in Open WebUI, a self-hosted artificial intelligence platform. Prior to version 0.9.6, the chat message listener allows non-same-origin input:prompt and action:submit messages, enabling an external site to set prompt text and trigger submitPrompt() in an authenticated victim session. This allows for cross-site forced actions and model/tool execution under vi [truncated]

MEDIUM open-webui CVE published 2026-06-23

CVE-2026-54006

CVE-2026-54006 is a medium-severity vulnerability in Open WebUI, a self-hosted artificial intelligence platform. The vulnerability exists in the POST /api/v1/calendars/events/{event_id}/update endpoint, which fails to validate the destination calendar_id supplied in the request body. This allows a regular user-role account to create an event in their own calendar and immediately move it into any other use [truncated]

HIGH open-webui CVE published 2026-06-18

CVE-2026-54017

CVE-2026-54017 is a high-severity vulnerability in Open WebUI, a self-hosted artificial intelligence platform. Prior to version 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segment before forwarding it to an admin-configured terminal server. This allows an authenticated user with granted access to a terminal server [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-45667

Open WebUI versions prior to 0.8.0 expose an unauthenticated API endpoint (`GET /api/v1/memories/ef`) that triggers embedding generation through `request.app.state.EMBEDDING_FUNCTION(...)`. This allows any unauthenticated remote attacker to invoke embedding operations, which can result in direct financial cost exposure when configured with paid embedding providers. The vulnerability represents a missing a [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-45666

Open WebUI versions prior to 0.8.11 contain an authorization bypass vulnerability in the `/api/v1/notes/{note_id}` API endpoint. Authenticated users can retrieve notes belonging to other users by guessing or enumerating UUIDs, resulting in unauthorized disclosure of potentially sensitive user data. The vulnerability stems from missing authorization checks on the note retrieval endpoint. This issue was pub [truncated]

HIGH open-webui CVE published 2026-05-15

CVE-2026-45665

A stored cross-site scripting (XSS) vulnerability in Open WebUI prior to version 0.8.0 allows a compromised administrator to inject malicious JavaScript into the global banner component. The root cause is an improper sanitization order where DOMPurify executes before the marked library processes content, enabling payload bypass. Because the banner renders for all users including the Super Admin, this vect [truncated]

MEDIUM open-webui CVE published 2026-05-15

CVE-2026-45365

## Summary Open WebUI versions prior to 0.8.11 expose an internal-only `bypass_filter` parameter on the `/openai/chat/completions` and `/ollama/api/chat` HTTP endpoints via FastAPI query string binding. Any authenticated user can append `?bypass_filter=true` to bypass model access control checks and invoke admin-restricted models. ## Technical Details The vulnerability stems from FastAPI's automatic query [truncated]