VYPR
High severity8.3NVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026

CVE-2026-56400

CVE-2026-56400

Description

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious cross-site requests from attacker-controlled websites when an admin user visits them.

Affected products

2
  • Openwebui/Open Webuillm-fuzzy2 versions
    <0.3.14+ 1 more
    • (no CPE)range: <0.3.14
    • cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*range: <0.3.14

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.