VYPR

Vendor CVEs

Openwebui

All CVEs

179 total · sorted by risk
  • CVE-2026-59226LowJul 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automations, and check_model_access only enforced…

  • CVE-2026-59215LowJul 9, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a message from another private or DM…

  • CVE-2026-29071LowMar 27, 2026
    risk 0.13cvss 3.1epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can read other users' private memories via `/api/v1/retrieval/query/collection`. Version 0.8.6 patches the issue.

  • CVE-2026-0766Jan 23, 2026
    risk 0.02cvss —epss 0.26

    Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue.…

  • CVE-2024-7959Mar 20, 2025
    risk 0.02cvss —epss 0.24

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-56400HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.01

    open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute arbitrary code on the openwebui instance by crafting malicious…

  • CVE-2026-56398HigJul 15, 2026
    risk 0.00cvss 7.3epss 0.01

    Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header, allowing SVG files to bypass the profile image validator and be…

  • CVE-2026-59214HigJul 9, 2026
    risk 0.00cvss 7.3epss 0.00

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and…

  • CVE-2026-56399MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal…

  • CVE-2026-0767Jan 23, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue.…

  • CVE-2026-0765Jan 23, 2026
    risk 0.00cvss —epss 0.02

    Rejected reason: Open WebU's investigation further investigation  showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue.…

  • CVE-2025-63391Dec 18, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2025-29446Apr 21, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2024-8060Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7990Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7806Mar 20, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7053Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7046Mar 20, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7045Mar 20, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7040Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7039Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7036Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7034Mar 20, 2025
    risk 0.00cvss —epss 0.02

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7033Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-12537Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-12534Mar 20, 2025
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7049Oct 10, 2024
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7037Oct 9, 2024
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7038Oct 9, 2024
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Page 4 of 4