Security Advisories for open-webui in pypi
High
29 days ago
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
pypi
open-webui
Moderate
29 days ago
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
pypi
open-webui
High
29 days ago
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
pypi
open-webui
Moderate
29 days ago
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
pypi
open-webui
Moderate
29 days ago
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
pypi
open-webui
Moderate
29 days ago
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
pypi
open-webui
Moderate
29 days ago
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
pypi
open-webui
Moderate
29 days ago
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
pypi
open-webui
High
29 days ago
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
pypi
open-webui
High
29 days ago
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
pypi
open-webui
Moderate
29 days ago
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
pypi
open-webui
Moderate
29 days ago
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
pypi
open-webui
Low
29 days ago
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
pypi
open-webui
High
29 days ago
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
pypi
open-webui
Moderate
29 days ago
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
pypi
open-webui
High
29 days ago
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
pypi
open-webui
High
about 1 month ago
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: Arena task endpoints can bypass underlying model access controls
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
pypi
open-webui
Low
about 1 month ago
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
pypi
open-webui
Low
about 1 month ago
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
pypi
open-webui
High
about 1 month ago
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
pypi
open-webui
High
about 1 month ago
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
pypi
open-webui
High
about 1 month ago
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
pypi
open-webui
Low
about 1 month ago
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
pypi
open-webui
Low
about 1 month ago
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
pypi
open-webui
Moderate
about 1 month ago
Open WebUI: Account enumeration via observable login timing discrepancy
pypi
open-webui
Moderate
about 2 months ago
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
pypi
open-webui
High
about 2 months ago
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
pypi
open-webui
High
about 2 months ago
Open WebUI vulnerable to Stored XSS via iFrame in citations model
pypi
open-webui
High
about 2 months ago
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
pypi
open-webui
Moderate
about 2 months ago
Open WebUI allows limited stored XSS vila uploaded html file
pypi
open-webui
Moderate
3 months ago
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
pypi
open-webui
Moderate
3 months ago
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
pypi
open-webui
High
3 months ago
Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
pypi
open-webui
High
3 months ago
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
pypi
open-webui
Moderate
3 months ago
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
pypi
open-webui
Moderate
3 months ago
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
pypi
open-webui
High
3 months ago
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
pypi
open-webui
High
3 months ago
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
pypi
open-webui
High
3 months ago
Open WebUI: Forged chat-file link allows cross-user file read and deletion
pypi
open-webui
Moderate
3 months ago
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
pypi
open-webui
High
3 months ago
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
pypi
open-webui
High
3 months ago
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
pypi
open-webui
Moderate
3 months ago
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
pypi
open-webui
High
4 months ago
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
pypi
open-webui
High
4 months ago
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
pypi
open-webui
High
4 months ago
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
pypi
open-webui
Moderate
4 months ago
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
pypi
open-webui
Moderate
4 months ago
Open WebUI has an Indirect Object Reference (IDOR) in user notes
pypi
open-webui
High
4 months ago
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
pypi
open-webui
High
4 months ago
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
pypi
open-webui
High
4 months ago
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
pypi
open-webui
High
4 months ago
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
pypi
open-webui
High
4 months ago
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
pypi
open-webui
High
4 months ago
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
pypi
open-webui
Moderate
4 months ago
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
pypi
open-webui
Moderate
4 months ago
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
pypi
open-webui
Moderate
4 months ago
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
pypi
open-webui
Moderate
4 months ago
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
pypi
open-webui
Moderate
4 months ago
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
pypi
open-webui
Moderate
4 months ago
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
pypi
open-webui
High
4 months ago
Open WebUI's chat completion API allows tool restrictions to be bypassed
pypi
open-webui
Moderate
4 months ago
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
pypi
open-webui
Moderate
4 months ago
Open WebUI missing authorization check at the model update function - models from other users can be updated
pypi
open-webui
High
4 months ago
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
pypi
open-webui
High
4 months ago
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
pypi
open-webui
Moderate
4 months ago
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
pypi
open-webui
Moderate
4 months ago
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
pypi
open-webui
Low
4 months ago
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
pypi
open-webui
High
4 months ago
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
pypi
open-webui
High
4 months ago
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
pypi
open-webui
High
4 months ago
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
pypi
open-webui
High
4 months ago
Open WebUI has inconsistent authorization controls within memories API
pypi
open-webui
Moderate
4 months ago
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
pypi
open-webui
High
4 months ago
Open WebUI has a CORS misconfiguration and session validation issue
pypi
open-webui
Moderate
4 months ago
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
pypi
open-webui
Moderate
4 months ago
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
pypi
open-webui
Moderate
4 months ago
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
pypi
open-webui
Moderate
4 months ago
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
pypi
open-webui