VDB
EN
MEDIUM 6.9

PYSEC-2026-1739

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)

빠른 조치

PYSEC-2026-1739 — open-webui: 아래 명령으로 수정 버전으로 올리세요.

pip install --upgrade 'open-webui>=0.3.16'

상세

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious site or through top-level navigation. The affected endpoints include /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads. This impacts both the availability and integrity of the application.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / open-webui
최초 영향 버전: 0 수정 버전: 0.3.16
수정 pip install --upgrade 'open-webui>=0.3.16'

참고