open-webui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45351Mediumopen-webui: Open WebUI Exposes System Prompt to Regular User [Non-Admin]CVE-2026-45350Highopen-webui: Open WebUI's chat completion API allows tool restrictions to be bypassedCVE-2026-45349Highopen-webui: Open WebUI has Broken Access Control for Completions APICVE-2026-45347Mediumopen-webui: Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate functionCVE-2026-45346Mediumopen-webui: Open WebUI Has Stored Cross-Site Scripting in SVG RendererCVE-2026-45345Mediumopen-webui: Open WebUI missing authorization check at the model update function - models from other users can be updatedCVE-2026-45338Highopen-webui: Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)CVE-2026-45331Highopen-webui: Open WebUI has a full SSRF Vulnerability in the RAG Web Search FeatureCVE-2026-45317Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL ManipulationCVE-2026-45318Mediumopen-webui: Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)CVE-2026-45316Lowopen-webui: Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)CVE-2026-45314Highopen-webui: Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/imageCVE-2026-45315Highopen-webui: Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptionsCVE-2026-45303Highopen-webui: Open WebUI has stored XSS via the HTML renedering viewCVE-2026-45301Highopen-webui: Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded fileCVE-2026-45299Mediumopen-webui: Open WebUI has Stored Cross-Site Scripting In Profile PictureCVE-2026-44570Highopen-webui: Open WebUI has inconsistent authorization controls within memories APICVE-2026-44571Mediumopen-webui: Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read PermissionCVE-2026-44569Highopen-webui: Open WebUI's Insecure Message Access Breaks AuthorizationCVE-2026-44565Highopen-webui: Open WebUI Arbitrary File Write, Delete via Path TraversalGHSA-6XCP-7MPR-M7WMHighopen-webui: Open WebUI has a CORS misconfiguration and session validation issueCVE-2026-44566Highopen-webui: Open WebUI Vulnerable to Arbitrary File Upload and Path TraversalCVE-2026-44567Highopen-webui: Open WebUI has Improper Authorization ControlCVE-2026-44549Highopen-webui: Open WebUI has stored XSS in Excel file previewCVE-2026-44568Mediumopen-webui: Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

Stop the waste.
Protect your environment with Kodem.