Medium severity6.5NVD Advisory· Published Aug 4, 2026· Updated Sep 18, 2026
CVE-2026-70491
CVE-2026-70491
Description
Open WebUI versions prior to 0.11.0 improperly exposed tool source code, potentially revealing sensitive credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-webuiPyPI | < 0.11.0 | 0.11.0 |
Affected products
1- Range: <=0.10.2
Patches
Vulnerability mechanics
References
5- github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491cnvdPatchWEB
- github.com/open-webui/open-webui/pull/27005nvdPatchVendor AdvisoryWEB
- github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vxnvdExploitPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-3r7g-q6cg-q2vxghsaADVISORY
- github.com/open-webui/open-webui/releases/tag/v0.11.0nvdRelease NotesWEB
News mentions
1- Open WebUI: 17 Vulnerabilities Disclosed Together, Patched in 0.11.0Vypr Intelligence · Aug 4, 2026