Open WebUIGHSA-frv8-gffc-37px
open-webui is Vulnerable to Incorrect Access Control
LowCVE-2025-63681 · Published Dec 4, 2025 · updated Jul 7, 2026
open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.6.33 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2025-63681, PYSEC-2026-1732
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 27 | Open WebUI has unauthorized deletion of knowledge files | Medium5.4 | 0.8.6 |
| Mar 27 | Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite | High7.1 | 0.8.6 |
| Mar 27 | Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions` | Medium4.3 | 0.8.6 |
| Dec 42025 | Open WebUI: server-side request forgery | High8.5 | 0.6.37 |
| Nov 72025 | Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events | High7.3 | 0.6.35 |
| Nov 72025 | Open WebUI: cross-site scripting | High8.7 | 0.6.35 |