open-webui
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting open-webui.
- CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange6.5
- CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange6.5
- CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history6.5
- CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets5.0
- CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree6.5
- CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch7.1
- CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion7.1
- CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions4.3
- CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader7.7
- CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin8.7
- CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint4.3
- CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends4.3
- CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite8.1
- CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication6.8
- CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes6.5