open-webui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54011Highopen-webui: Open WebUI: Stored XSS in Mermaid Markdown PreviewCVE-2026-54010Highopen-webui: Open WebUI: Forged chat-file link allows cross-user file read and deletionCVE-2026-54009Mediumopen-webui: Open WebUI: Cross-user file disclosure via /api/chat/completions image_url fieldCVE-2026-54008Highopen-webui: Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)CVE-2026-54007Highopen-webui: Open WebUI: Cross-origin postMessage confirmation bypass via action:submitCVE-2026-54006Mediumopen-webui: Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendarCVE-2026-45675Highopen-webui: Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin AccountsCVE-2026-45672Highopen-webui: Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassedCVE-2026-45671Highopen-webui: Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletionCVE-2026-45667Mediumopen-webui: Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)CVE-2026-45666Mediumopen-webui: Open WebUI has an Indirect Object Reference (IDOR) in user notesCVE-2026-45665Highopen-webui: Open WebUI has Stored XSS in Banner Component via Improper Sanitization OrderCVE-2026-45402Highopen-webui: Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach EndpointsGHSA-3WGJ-C2HG-VM6QHighopen-webui: Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_urlCVE-2026-45401Highopen-webui: Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)CVE-2026-45400Highopen-webui: Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`CVE-2026-45399Highopen-webui: Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruptionCVE-2026-45398Highopen-webui: Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access ControlsCVE-2026-45397Mediumopen-webui: Open WebUI Vulnerable to Unauthenticated RAG Configuration DisclosureCVE-2026-45396Mediumopen-webui: Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data ManipulationCVE-2026-45395Highopen-webui: Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code ExecutionCVE-2026-45387Mediumopen-webui: Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)CVE-2026-45386Mediumopen-webui: Open WebUI has an IDOR vulnerability in the pin_channel_message API endpointCVE-2026-45385Mediumopen-webui: Open WebUI has an IDOR vulnerability in the update_message_by_id API endpointCVE-2026-45365Mediumopen-webui: Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

Stop the waste.
Protect your environment with Kodem.