CRITICAL9.1CVE-2026-44551Open WebUI has an LDAP Empty Password Authentication Bypass from 0, < 0.9.0
HIGH8.8CVE-2026-45672Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed from 0, < 0.8.12
HIGH8.8CVE-2026-45672Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed from 0, < 0.8.12
HIGH8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
from 0, < 0.9.6
HIGH8.7Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
from 0, < 0.9.3
HIGH8.7Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
from 0, < 0.9.3
HIGH8.7Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
from 0, < 0.9.0
HIGH8.7Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
from 0, < 0.9.0
HIGH8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
from 0, < 0.9.6
HIGH8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
from 0, < 0.9.6
HIGH8.5Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
from 0, < 0.9.5
HIGH8.5Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
from 0, < 0.9.5
HIGH8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
from 0, < 0.9.5
HIGH8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
from 0, < 0.9.5
HIGH8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
from 0, < 0.9.0
HIGH8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
from 0, < 0.9.0
HIGH8.5Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
from 0, < 0.6.37
HIGH8.5Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
from 0, < 0.6.37
HIGH8.4Open WebUI stored cross-site scripting (XSS) vulnerability
from 0, <= 0.3.8
HIGH8.4Open WebUI stored cross-site scripting (XSS) vulnerability
from 0, <= 0.3.8
HIGH8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
from 0, < 0.9.6
HIGH8.3Open WebUI has inconsistent authorization controls within memories API
from 0, < 0.6.19
HIGH8.3Open WebUI has inconsistent authorization controls within memories API
from 0, < 0.6.19
HIGH8.3Open WebUI has a CORS misconfiguration and session validation issue
from 0, < 0.3.33
HIGH8.3Open WebUI Allows Admin Deletion via API Endpoint
from 0, <= 0.3.8
HIGH8.3Open WebUI Allows Admin Deletion via API Endpoint
from 0, <= 0.3.8
HIGH8.1Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
from 0, < 0.9.0
HIGH8.1Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
from 0, < 0.9.5
HIGH8.1Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
from 0, < 0.9.5
HIGH8.1Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
from 0, < 0.3.16
HIGH8.1Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
from 0, < 0.3.16
HIGH8.1Open WebUI Arbitrary File Write, Delete via Path Traversal
from 0, < 0.6.10
HIGH8.1Open WebUI Arbitrary File Write, Delete via Path Traversal
from 0, < 0.6.10
HIGH8.1Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
from 0, < 0.9.0
HIGH8.1Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
from 0, < 0.9.0
HIGH8.1Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
from 0, < 0.9.0
HIGH8.1Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
from 0, < 0.9.0
HIGH8.1Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
from 0, < 0.5.17
HIGH8.1Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
from 0, < 0.5.17
HIGH8.1Open WebUI Allows Arbitrary File Reading and Deletion
from 0, <= 0.3.8
HIGH8.1Open WebUI Allows Arbitrary File Reading and Deletion
from 0, <= 0.3.8
HIGH8.0Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
from 0, < 0.9.0
HIGH8.0Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
from 0, < 0.9.0
HIGH8.0Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
from 0, < 0.3.33
HIGH8.0Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
from 0, < 0.3.33
HIGH7.7Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
from 0, < 0.9.6
HIGH7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
from 0, < 0.9.6
HIGH7.7Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
from 0, < 0.9.0
HIGH7.7Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
from 0, < 0.9.0
HIGH7.7Open WebUI has stored XSS via the HTML renedering view
from 0, < 0.6.5
HIGH7.7Open WebUI has stored XSS via the HTML renedering view
from 0, < 0.6.5
HIGH7.7Open WebUI has Broken Access Control in Tool Valves
from 0, < 0.8.11
HIGH7.7Open WebUI has Broken Access Control in Tool Valves
from 0, < 0.8.11
HIGH7.7Open WebUI has SSRF in /openai/models
from 0, <= 0.3.8
HIGH7.7Open WebUI has SSRF in /openai/models
from 0, <= 0.3.8
HIGH7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
from 0, < 0.9.6
HIGH7.6Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
from 0, < 0.9.0
HIGH7.6Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
from 0, < 0.9.0
HIGH7.6Open WebUI Vulnerable to a Session Fixation Attack
from 0, <= 0.3.8
HIGH7.6Open WebUI Vulnerable to a Session Fixation Attack
from 0, <= 0.3.8
HIGH7.5Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
from 0, < 0.9.5
HIGH7.5Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
from 0, < 0.9.5
HIGH7.5Open WebUI denial of service through endpoint for converting markdown
from 0, <= 0.3.8
HIGH7.5Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
from 0, <= 0.3.10
HIGH7.5Open WebUI denial of service through endpoint for converting markdown
from 0, <= 0.3.8
HIGH7.5Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
from 0, <= 0.3.10
HIGH7.5Open WebUI Uncontrolled Resource Consumption vulnerability
from 0, <= 0.3.8
HIGH7.5Open WebUI Uncontrolled Resource Consumption vulnerability
from 0, <= 0.3.8
HIGH7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
from 0, < 0.6.44
HIGH7.3Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
from 0, < 0.6.44
HIGH7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
from 0, < 0.7.0
HIGH7.3Open WebUI vulnerable to Stored XSS via iFrame in citations model
from 0, < 0.7.0
HIGH7.3Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
from 0, < 0.9.5
HIGH7.3Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
from 0, < 0.1.124
HIGH7.3Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
from 0, < 0.1.124
HIGH7.3Open WebUI has Improper Authorization Control
from 0, < 0.1.124
HIGH7.3Open WebUI has Improper Authorization Control
from 0, < 0.1.124
HIGH7.3Open WebUI has stored XSS in Excel file preview
from 0, < 0.8.0
HIGH7.3Open WebUI has stored XSS in Excel file preview
from 0, < 0.8.0
HIGH7.3open-webui Vulnerable to Stored XSS via Model Description
from 0, < 0.9.0
HIGH7.3open-webui Vulnerable to Stored XSS via Model Description
from 0, < 0.9.0
HIGH7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
from 0, < 0.9.6
HIGH7.1Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
from 0, < 0.9.0
HIGH7.1Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
from 0, < 0.9.0
HIGH7.1Open WebUI's chat completion API allows tool restrictions to be bypassed
from 0, < 0.8.6
HIGH7.1Open WebUI's chat completion API allows tool restrictions to be bypassed
from 0, < 0.8.6
HIGH7.1Open WebUI has Broken Access Control for Completions API
from 0, < 0.9.0
HIGH7.1Open WebUI has Broken Access Control for Completions API
from 0, < 0.9.0
HIGH7.1Open WebUI's Insecure Message Access Breaks Authorization
from 0, < 0.6.19
HIGH7.1Open WebUI's Insecure Message Access Breaks Authorization
from 0, < 0.6.19
HIGH7.1Open WebUI's responses passthrough endpoint lacks access control authorization
from 0, < 0.9.0
HIGH7.1Open WebUI's responses passthrough endpoint lacks access control authorization
from 0, < 0.9.0
HIGH7.1Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
from 0, < 0.8.6
HIGH7.1Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
from 0, < 0.8.6
MEDIUM6.9Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
from 0, <= 0.3.8
MEDIUM6.9Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
from 0, <= 0.3.8
MEDIUM6.8Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
from 0, <= 0.3.8
MEDIUM6.8Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
from 0, <= 0.3.8
MEDIUM6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
from 0, < 0.9.6
MEDIUM6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
from 0, < 0.9.6