MEDIUM 6.9
PYSEC-2026-1739
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
빠른 조치
PYSEC-2026-1739 — open-webui: 아래 명령으로 수정 버전으로 올리세요.
pip install --upgrade 'open-webui>=0.3.16' 상세
In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious site or through top-level navigation. The affected endpoints include /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads. This impacts both the availability and integrity of the application.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.