| Sep 10 | Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange CVE-2026-88006Medium6.5fixed in 0.11.1 | Medium6.5 | 0.11.1 |
| Sep 10 | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout CVE-2026-87011High7.5fixed in 0.11.1 | High7.5 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value CVE-2026-87012Medium4.3fixed in 0.11.1 | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle CVE-2026-87013Medium4.3fixed in 0.11.1 | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes CVE-2026-87014Medium6.5fixed in 0.11.1 | Medium6.5 | 0.11.1 |
| Sep 10 | Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication CVE-2026-87015Medium6.8fixed in 0.11.1 | Medium6.8 | 0.11.1 |
| Sep 10 | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite CVE-2026-87016High8.1fixed in 0.11.1 | High8.1 | 0.11.1 |
| Sep 10 | Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends CVE-2026-87017Medium4.3fixed in 0.11.1 | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint CVE-2026-87994Medium4.3fixed in 0.11.1 | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin CVE-2026-87995High8.7fixed in 0.11.1 | High8.7 | 0.11.1 |
| Sep 10 | Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader CVE-2026-87996High7.7fixed in 0.11.1 | High7.7 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions CVE-2026-87997Medium4.3fixed in 0.11.1 | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion CVE-2026-87998High7.1fixed in 0.11.1 | High7.1 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch CVE-2026-87999High7.1fixed in 0.11.1 | High7.1 | 0.11.1 |
| Sep 10 | Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange CVE-2026-88005Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| Sep 9 | Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree CVE-2026-88000Medium6.5fixed in 0.11.1 | Medium6.5 | 0.11.1 |
| Sep 9 | Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets CVE-2026-88001Medium5.0fixed in 0.11.1 | Medium5.0 | 0.11.1 |
| Sep 9 | Open WebUI: Any authenticated user can hang the server via a cyclic chat message history CVE-2026-88002Medium6.5fixed in 0.11.1 | Medium6.5 | 0.11.1 |
| Aug 4 | Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder CVE-2026-70494High8.1fixed in 0.11.0 | High8.1 | 0.11.0 |
| Aug 4 | Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically CVE-2026-70493Medium6.5fixed in 0.11.0 | Medium6.5 | 0.11.0 |
| Aug 4 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages CVE-2026-70492High8.7fixed in 0.11.0 | High8.7 | 0.11.0 |
| Aug 4 | Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints CVE-2026-70491Medium6.5fixed in 0.11.0 | Medium6.5 | 0.11.0 |
| Aug 4 | Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check CVE-2026-70490Medium6.3fixed in 0.11.0 | Medium6.3 | 0.11.0 |
| Aug 4 | Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing CVE-2026-70489Medium6.5fixed in 0.11.0 | Medium6.5 | 0.11.0 |
| Aug 4 | Open WebUI: DNS Rebinding SSRF Bypass CVE-2026-54020Medium6.3fixed in 0.11.0 | Medium6.3 | 0.11.0 |
| Aug 4 | Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata CVE-2026-70487Medium5.3fixed in 0.11.0 | Medium5.3 | 0.11.0 |
| Aug 4 | Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup CVE-2026-70488Medium4.3fixed in 0.11.0 | Medium4.3 | 0.11.0 |
| Aug 4 | Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin CVE-2026-70486High8.2fixed in 0.11.0 | High8.2 | 0.11.0 |
| Aug 4 | Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs CVE-2026-70485High7.1fixed in 0.11.0 | High7.1 | 0.11.0 |
| Aug 4 | Open WebUI: Users denied the image-generation permission can still generate images via chat completions CVE-2026-70484Medium4.3fixed in 0.11.0 | Medium4.3 | 0.11.0 |
| Aug 4 | Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering CVE-2026-70480Medium4.1fixed in 0.11.0 | Medium4.1 | 0.11.0 |
| Aug 4 | Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint CVE-2026-70483Low3.1fixed in 0.11.0 | Low3.1 | 0.11.0 |
| Aug 4 | Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client CVE-2026-70482High8.1fixed in 0.11.0 | High8.1 | 0.11.0 |
| Aug 4 | Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages CVE-2026-70481Medium5.4fixed in 0.11.0 | Medium5.4 | 0.11.0 |
| Aug 4 | Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader CVE-2026-70479High7.7fixed in 0.11.0 | High7.7 | 0.11.0 |
| Jul 24 | open-webui terminal proxy path traversal guard bypass via 9x encoded traversal CVE-2026-59221High7.7fixed in 0.10.0 | High7.7 | 0.10.0 |
| Jul 24 | Open WebUI: Arena task endpoints can bypass underlying model access controls CVE-2026-59225Medium5.4fixed in 0.10.0 | Medium5.4 | 0.10.0 |
| Jul 24 | Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete CVE-2026-59212Medium5.4fixed in 0.10.0 | Medium5.4 | 0.10.0 |
| Jul 24 | Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) CVE-2026-59224High8.0fixed in 0.10.0 | High8.0 | 0.10.0 |
| Jul 24 | Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching CVE-2026-59223Medium4.3fixed in 0.10.0 | Medium4.3 | 0.10.0 |
| Jul 24 | Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials CVE-2026-59222Mediumfixed in 0.10.0 | Medium | 0.10.0 |
| Jul 24 | Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding CVE-2026-59215Low3.1fixed in 0.10.0 | Low3.1 | 0.10.0 |
| Jul 24 | Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) CVE-2026-59213Low3.5fixed in 0.10.0 | Low3.5 | 0.10.0 |
| Jul 24 | Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) CVE-2026-59217Medium4.3fixed in 0.10.0 | Medium4.3 | 0.10.0 |
| Jul 24 | Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id CVE-2026-59216High7.7fixed in 0.10.0 | High7.7 | 0.10.0 |
| Jul 24 | Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) CVE-2026-59714High7.1fixed in 0.10.0 | High7.1 | 0.10.0 |
| Jul 24 | Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout CVE-2026-59219High7.1fixed in 0.10.0 | High7.1 | 0.10.0 |
| Jul 24 | Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave) CVE-2026-59715Low3.1fixed in 0.10.0 | Low3.1 | 0.10.0 |
| Jul 24 | Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission CVE-2026-59227Medium4.3fixed in 0.10.0 | Medium4.3 | 0.10.0 |
| Jul 24 | Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config CVE-2026-59220Medium6.5fixed in 0.10.0 | Medium6.5 | 0.10.0 |
| Jul 24 | Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation CVE-2026-59226Low3.1fixed in 0.10.0 | Low3.1 | 0.10.0 |
| Jul 24 | Open WebUI: Account enumeration via observable login timing discrepancy CVE-2026-59218Medium5.3fixed in 0.10.0 | Medium5.3 | 0.10.0 |
| Jul 24 | Open WebUI: Stored web worker XSS via Pyodide CVE-2026-59214High7.3fixed in 0.10.0 | High7.3 | 0.10.0 |
| Jul 23 | Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header , full message processing on restricted endpoints CVE-2026-45339Medium6.5fixed in 0.9.0 | Medium6.5 | 0.9.0 |
| Jul 7 | Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality CVE-2026-34225Medium4.3no fix yet | Medium4.3 | No fix yet |
| Jul 7 | Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages CVE-2026-26193High7.3fixed in 0.6.44 | High7.3 | 0.6.44 |
| Jul 7 | Open WebUI vulnerable to Stored XSS via iFrame in citations model CVE-2026-26192High7.3fixed in 0.7.0 | High7.3 | 0.7.0 |
| Jul 7 | Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions CVE-2025-46719Highfixed in 0.6.6 | High | 0.6.6 |
| Jul 7 | Open WebUI allows limited stored XSS vila uploaded html file CVE-2025-46571Mediumfixed in 0.6.6 | Medium | 0.6.6 |
| Jun 17 | Open WebUI: Any authenticated user can read other users' private notes via Socket.IO CVE-2026-54022Medium5.3fixed in 0.8.11 | Medium5.3 | 0.8.11 |