VDB
KO

package

npm / open-webui

pkg:npm/open-webui

HIGH 7.5 npm PyPI
GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

Modified: 4/15/2025

HIGH 7.2 npm
GHSA-p4fx-23fq-jfg6 · CVE-2026-45395

Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution

Modified: 5/16/2026

HIGH 8.7 npm PyPI
GHSA-w7xj-8fx7-wfch · CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Modified: 11/27/2025