VDB
KO

package

PyPI / open-webui

pkg:pypi/open-webui

HIGH 7.5 npm PyPI
GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

Modified: 4/15/2025

HIGH 8.7 npm PyPI
GHSA-w7xj-8fx7-wfch · CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Modified: 11/27/2025

HIGH 7.3 PyPI
GHSA-3wgj-c2hg-vm6q

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

Modified: 5/14/2026

HIGH 8.7 PyPI
GHSA-3x8w-4f7p-xxc2 · CVE-2026-44552

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

Modified: 5/16/2026

HIGH 7.5 PyPI
GHSA-6wj5-5pgr-jwq8

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file

Modified: 4/15/2025

HIGH 8.3 PyPI
GHSA-6xcp-7mpr-m7wm

Open WebUI has a CORS misconfiguration and session validation issue

Modified: 5/11/2026

HIGH 7.1 PyPI
GHSA-8jjp-r2w2-4v22 · CVE-2026-45399

Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption

Modified: 5/16/2026

HIGH 8.5 PyPI
GHSA-c6xv-rcvw-v685 · CVE-2025-65958

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

Modified: 12/5/2025

HIGH 8.1 PyPI
GHSA-r8wh-8m7r-fh33 · CVE-2026-45301

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

Modified: 5/19/2026

HIGH 8.5 PyPI
GHSA-rh5x-h6pp-cjj6 · CVE-2026-45401

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Modified: 5/16/2026

MEDIUM 5.4 PyPI
GHSA-rjmp-vjf2-qf4g · CVE-2026-45396

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

Modified: 5/16/2026

HIGH 7.5 PyPI
GHSA-w466-2wfc-8g58

Open WebUI has vulnerable dependency on starlette via fastapi

Modified: 4/15/2025