open-webui
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting open-webui.
- CVE-2026-70494Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder8.1
- CVE-2026-70493Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically6.5
- CVE-2026-70492Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages8.7
- CVE-2026-70491Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints6.5
- CVE-2026-70490Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check6.3
- CVE-2026-70489Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing6.5
- CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypass6.3
- CVE-2026-70488Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup4.3
- CVE-2026-70487Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata5.3
- CVE-2026-70486Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin8.2
- CVE-2026-70485Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs7.1
- CVE-2026-70484Open WebUI: Users denied the image-generation permission can still generate images via chat completions4.3
- CVE-2026-70483Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint3.1
- CVE-2026-70482Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client8.1
- CVE-2026-70481Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages5.4