Security Advisories for open-webui in pypi
High
6 days ago
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
pypi, npm
open-webui
High
6 days ago
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
pypi, npm
open-webui
High
8 months ago
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
pypi, npm
open-webui
High
8 months ago
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
pypi
open-webui
High
8 months ago
Open WebUI denial of service through endpoint for converting markdown
pypi
open-webui
High
8 months ago
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
pypi
open-webui
High
8 months ago
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file
pypi
open-webui
Moderate
8 months ago
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
pypi
open-webui
Moderate
8 months ago
Open WebUI Allows Arbitrary File Write via the `/models/upload` Endpoint
pypi
open-webui
Moderate
8 months ago
Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
pypi
open-webui
Moderate
8 months ago
Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
pypi
open-webui
Moderate
about 1 year ago
open-webui Insecure Direct Object Reference (IDOR) vulnerability
pypi
open-webui
Low
about 1 year ago
open-webui allows enumeration of file names and traversal of directories by observing the error messages
pypi
open-webui