VDB
EN

PYSEC-2026-1732

open-webui is Vulnerable to Incorrect Access Control

빠른 조치

PYSEC-2026-1732 — open-webui: 아래 명령으로 수정 버전으로 올리세요.

pip install --upgrade 'open-webui>=0.9.0'

상세

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / open-webui
최초 영향 버전: 0 수정 버전: 0.9.0
수정 pip install --upgrade 'open-webui>=0.9.0'

참고