Skip to content

Open WebUI security advisories

161 advisories · 65 critical or high in 12 months · latest Sep 10

60 of 161 advisories

DateAdvisory
Sep 10Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
CVE-2026-88006Medium6.5fixed in 0.11.1
Sep 10Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
CVE-2026-87011High7.5fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
CVE-2026-87012Medium4.3fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
CVE-2026-87013Medium4.3fixed in 0.11.1
Sep 10Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
CVE-2026-87014Medium6.5fixed in 0.11.1
Sep 10Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
CVE-2026-87015Medium6.8fixed in 0.11.1
Sep 10Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
CVE-2026-87016High8.1fixed in 0.11.1
Sep 10Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
CVE-2026-87017Medium4.3fixed in 0.11.1
Sep 10Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
CVE-2026-87994Medium4.3fixed in 0.11.1
Sep 10Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
CVE-2026-87995High8.7fixed in 0.11.1
Sep 10Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
CVE-2026-87996High7.7fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
CVE-2026-87997Medium4.3fixed in 0.11.1
Sep 10Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
CVE-2026-87998High7.1fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
CVE-2026-87999High7.1fixed in 0.11.1
Sep 10Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
CVE-2026-88005Medium6.5fixed in 0.9.0
Sep 9Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
CVE-2026-88000Medium6.5fixed in 0.11.1
Sep 9Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
CVE-2026-88001Medium5.0fixed in 0.11.1
Sep 9Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
CVE-2026-88002Medium6.5fixed in 0.11.1
Aug 4Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
CVE-2026-70494High8.1fixed in 0.11.0
Aug 4Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
CVE-2026-70493Medium6.5fixed in 0.11.0
Aug 4Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
CVE-2026-70492High8.7fixed in 0.11.0
Aug 4Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
CVE-2026-70491Medium6.5fixed in 0.11.0
Aug 4Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
CVE-2026-70490Medium6.3fixed in 0.11.0
Aug 4Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
CVE-2026-70489Medium6.5fixed in 0.11.0
Aug 4Open WebUI: DNS Rebinding SSRF Bypass
CVE-2026-54020Medium6.3fixed in 0.11.0
Aug 4Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
CVE-2026-70487Medium5.3fixed in 0.11.0
Aug 4Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
CVE-2026-70488Medium4.3fixed in 0.11.0
Aug 4Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
CVE-2026-70486High8.2fixed in 0.11.0
Aug 4Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
CVE-2026-70485High7.1fixed in 0.11.0
Aug 4Open WebUI: Users denied the image-generation permission can still generate images via chat completions
CVE-2026-70484Medium4.3fixed in 0.11.0
Aug 4Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
CVE-2026-70480Medium4.1fixed in 0.11.0
Aug 4Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
CVE-2026-70483Low3.1fixed in 0.11.0
Aug 4Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
CVE-2026-70482High8.1fixed in 0.11.0
Aug 4Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
CVE-2026-70481Medium5.4fixed in 0.11.0
Aug 4Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
CVE-2026-70479High7.7fixed in 0.11.0
Jul 24open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-59221High7.7fixed in 0.10.0
Jul 24Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59225Medium5.4fixed in 0.10.0
Jul 24Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59212Medium5.4fixed in 0.10.0
Jul 24Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-59224High8.0fixed in 0.10.0
Jul 24Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59223Medium4.3fixed in 0.10.0
Jul 24Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2026-59222Mediumfixed in 0.10.0
Jul 24Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
CVE-2026-59215Low3.1fixed in 0.10.0
Jul 24Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVE-2026-59213Low3.5fixed in 0.10.0
Jul 24Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59217Medium4.3fixed in 0.10.0
Jul 24Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVE-2026-59216High7.7fixed in 0.10.0
Jul 24Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
CVE-2026-59714High7.1fixed in 0.10.0
Jul 24Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVE-2026-59219High7.1fixed in 0.10.0
Jul 24Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVE-2026-59715Low3.1fixed in 0.10.0
Jul 24Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59227Medium4.3fixed in 0.10.0
Jul 24Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVE-2026-59220Medium6.5fixed in 0.10.0
Jul 24Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59226Low3.1fixed in 0.10.0
Jul 24Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-59218Medium5.3fixed in 0.10.0
Jul 24Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-59214High7.3fixed in 0.10.0
Jul 23Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header , full message processing on restricted endpoints
CVE-2026-45339Medium6.5fixed in 0.9.0
Jul 7Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-34225Medium4.3no fix yet
Jul 7Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
CVE-2026-26193High7.3fixed in 0.6.44
Jul 7Open WebUI vulnerable to Stored XSS via iFrame in citations model
CVE-2026-26192High7.3fixed in 0.7.0
Jul 7Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
CVE-2025-46719Highfixed in 0.6.6
Jul 7Open WebUI allows limited stored XSS vila uploaded html file
CVE-2025-46571Mediumfixed in 0.6.6
Jun 17Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-54022Medium5.3fixed in 0.8.11
About Open WebUI

The self-hosted chat interface for local and hosted models.

Packages watched: open-webui (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.