open-webui vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44560Mediumopen-webui: Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector SearchCVE-2026-44561Mediumopen-webui: Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM ChannelsCVE-2026-44564Mediumopen-webui: Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IOCVE-2026-44563Mediumopen-webui: Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/showCVE-2026-44562Mediumopen-webui: Open WebUI's Model Import Overwrites Any Model Without Ownership CheckCVE-2026-44559Mediumopen-webui: Open WebUI Missing Access Check on Channel Members Endpoint for Standard ChannelsCVE-2026-44557Mediumopen-webui: Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-CollectionCVE-2026-44554Highopen-webui: Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection OverwriteCVE-2026-44558Mediumopen-webui: Open WebUI's Channel Access Grants Bypass filter_allowed_access_grantsCVE-2026-44556Highopen-webui: Open WebUI's responses passthrough endpoint lacks access control authorizationCVE-2026-44555Highopen-webui: Open WebUI's Base Model Routing Bypasses Access Control via Model ChainingCVE-2026-44552Highopen-webui: Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache PoisoningCVE-2026-44553Highopen-webui: Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note AccessCVE-2026-44550Mediumopen-webui: Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' AccountsCVE-2026-44551Criticalopen-webui: Open WebUI has an LDAP Empty Password Authentication BypassCVE-2026-44721Highopen-webui: open-webui Vulnerable to Stored XSS via Model DescriptionCVE-2026-34222Highopen-webui: Open WebUI has Broken Access Control in Tool ValvesCVE-2026-29071Lowopen-webui: Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memoriesCVE-2026-29070Mediumopen-webui: Open WebUI has unauthorized deletion of knowledge filesCVE-2026-28788Highopen-webui: Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwriteCVE-2026-28786Mediumopen-webui: Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`CVE-2025-65959Highopen-webui: Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'CVE-2025-65958Highopen-webui: Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/webCVE-2025-63681Lowopen-webui: open-webui is Vulnerable to Incorrect Access ControlCVE-2025-64496Highopen-webui: Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

Stop the waste.
Protect your environment with Kodem.