Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Modified: 7/13/2026
package
pkg:pypi/open-webui
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Modified: 7/13/2026
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Modified: 7/13/2026
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Modified: 7/13/2026
Open WebUI has unauthorized deletion of knowledge files
Modified: 7/13/2026
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Modified: 9/10/2026
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Modified: 8/10/2026
Open WebUI has an LDAP Empty Password Authentication Bypass
Modified: 6/29/2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Modified: 8/4/2026
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Modified: 9/10/2026
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Modified: 7/13/2026
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
Modified: 8/10/2026
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Modified: 9/10/2026
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
Modified: 9/10/2026
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Modified: 9/10/2026
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
Modified: 8/10/2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Modified: 8/10/2026
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
Modified: 7/20/2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Modified: 7/16/2026
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Modified: 8/4/2026
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Modified: 7/13/2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Modified: 8/19/2026
Open WebUI Vulnerable to a Session Fixation Attack
Modified: 7/7/2026
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Modified: 7/13/2026
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
Modified: 7/13/2026
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
Modified: 7/13/2026
Open WebUI's chat completion API allows tool restrictions to be bypassed
Modified: 7/13/2026
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Modified: 9/10/2026
Open WebUI: Stored web worker XSS via Pyodide
Modified: 8/4/2026
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Modified: 7/20/2026
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
Modified: 9/10/2026
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Modified: 7/13/2026
Open WebUI has Improper Authorization Control
Modified: 7/13/2026
Open WebUI has stored XSS via the HTML renedering view
Modified: 7/13/2026
open-webui allows writing and deleting arbitrary files
Modified: 9/10/2026
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
Modified: 7/13/2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Modified: 8/10/2026
Open WebUI Stored Cross-Site Scripting Vulnerability
Modified: 7/7/2026
Open WebUI denial of service through endpoint for converting markdown
Modified: 7/7/2026
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Modified: 9/10/2026
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Modified: 7/13/2026
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Modified: 7/13/2026
Open WebUI has Stored Cross-Site Scripting In Profile Picture
Modified: 7/13/2026
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability in api/chat/file
Modified: 4/15/2025
Open WebUI has a CORS misconfiguration and session validation issue
Modified: 7/16/2026
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Modified: 8/10/2026
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
Modified: 8/19/2026
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
Modified: 8/4/2026
Open WebUI has Broken Access Control in Tool Valves
Modified: 7/13/2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Modified: 8/4/2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Modified: 8/4/2026
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Modified: 7/13/2026
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
Modified: 7/13/2026
Open WebUI: Account enumeration via observable login timing discrepancy
Modified: 8/4/2026
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Modified: 8/4/2026
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
Modified: 7/7/2026
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
Modified: 7/20/2026
Open WebUI allows limited stored XSS vila uploaded html file
Modified: 7/13/2026
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Modified: 7/13/2026
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
Modified: 9/10/2026
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Modified: 7/13/2026
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Modified: 8/10/2026
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Modified: 7/13/2026
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
Modified: 7/13/2026
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Modified: 7/20/2026
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
Modified: 7/7/2026
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
Modified: 7/13/2026
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
Modified: 7/7/2026
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
Modified: 7/7/2026
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
Modified: 7/13/2026
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Modified: 7/20/2026
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Modified: 7/20/2026
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
Modified: 7/13/2026
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
Modified: 7/7/2026
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Modified: 8/4/2026
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Modified: 9/10/2026
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Modified: 7/13/2026
open-webui is Vulnerable to Incorrect Access Control
Modified: 7/7/2026
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
Modified: 8/4/2026
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Modified: 8/10/2026
Open WebUI has Broken Access Control for Completions API
Modified: 7/13/2026
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Modified: 8/4/2026
Open WebUI stored cross-site scripting (XSS) vulnerability
Modified: 7/7/2026
Open WebUI missing authorization check at the model update function - models from other users can be updated
Modified: 7/13/2026
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Modified: 8/4/2026
Open WebUI Allows Viewing of Admin Details
Modified: 7/7/2026
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Modified: 7/13/2026
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Modified: 7/13/2026
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Modified: 7/15/2026
Open WebUI: DNS Rebinding SSRF Bypass
Modified: 8/10/2026
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Modified: 7/13/2026
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
Modified: 7/13/2026
Open WebUI has inconsistent authorization controls within memories API
Modified: 7/13/2026
Open WebUI's responses passthrough endpoint lacks access control authorization
Modified: 7/13/2026
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Modified: 7/13/2026
Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
Modified: 7/7/2026
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Modified: 7/20/2026
Open WebUI Arbitrary File Write, Delete via Path Traversal
Modified: 7/13/2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Modified: 8/4/2026
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Modified: 7/13/2026
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Modified: 7/13/2026