open-webui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59217Mediumopen-webui: Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)CVE-2026-59216Highopen-webui: Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idCVE-2026-59714Highopen-webui: Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)CVE-2026-59219Highopen-webui: Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logoutCVE-2026-59715Lowopen-webui: Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)CVE-2026-59227Mediumopen-webui: Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permissionCVE-2026-59220Mediumopen-webui: Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default configCVE-2026-59226Lowopen-webui: Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocationCVE-2026-59218Mediumopen-webui: Open WebUI: Account enumeration via observable login timing discrepancyCVE-2026-59214Highopen-webui: Open WebUI: Stored web worker XSS via PyodideCVE-2026-34225Mediumopen-webui: Open WebUI has Blind Server Side Request Forgery in its Image Edit FunctionalityCVE-2026-26193Highopen-webui: Open WebUI vulnerable to Stored XSS via iFrame embeds in response messagesCVE-2026-26192Highopen-webui: Open WebUI vulnerable to Stored XSS via iFrame in citations modelCVE-2025-46719Highopen-webui: Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via…CVE-2025-46571Mediumopen-webui: Open WebUI allows limited stored XSS vila uploaded html fileCVE-2026-54022Mediumopen-webui: Open WebUI: Any authenticated user can read other users' private notes via Socket.IOCVE-2026-54021Mediumopen-webui: Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameterCVE-2026-54019Mediumopen-webui: Open WebUI: RAG ACL Bypass in Milvus Multitenancy ModeCVE-2026-54018Highopen-webui: Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP RedirectsCVE-2026-54017Highopen-webui: Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversalCVE-2026-54016Mediumopen-webui: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File EnumerationCVE-2026-54015Mediumopen-webui: Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletionCVE-2026-54014Mediumopen-webui: Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}CVE-2026-54013Highopen-webui: Open WebUI: Stored XSS to Account Takeover via Model Profile Images CVE-2026-54012Highopen-webui: Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Stop the waste.
Protect your environment with Kodem.