Where
-Infinity
0

Vendor Risk Score

See how openwebui compares to other vendors in security performance

View Risk Score →

open-webuiopen-webui - Remote Code Execution via CORS Misconfiguration and Session Validation

Risk 80
Severity
9
First published (updated )

Open WebUI Open WebUIOpen WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI

Risk 74
Severity
8.5
First published (updated )

Open WebUI Open WebUIopen-webui terminal proxy path traversal guard bypass via 9x encoded traversal

Risk 44
Severity
7.7
First published (updated )

Open WebUI Open WebUIOpen WebUI: Arena task endpoints can bypass underlying model access controls

Risk 46
Severity
6.3
First published (updated )

Open WebUI Open WebUIOpen WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Risk 67
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Open WebUI Open WebUIOpen WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Risk 34
Severity
5.4
First published (updated )

Open WebUI Open WebUIOpen WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Risk 22
Severity
4.3
First published (updated )

Open WebUIOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Risk 38
Severity
6
First published (updated )

Open WebUIOpen WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

Risk 17
Severity
3.1
First published (updated )

Open WebUIOpen WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Open WebUI Open WebUIOpen WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Risk 22
Severity
4.3
First published (updated )

Open WebUIOpen WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id

Risk 74
Severity
9
First published (updated )

Open WebUI Open WebUIOpen WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Risk 48
Severity
7.1
First published (updated )

Open WebUI Open WebUIOpen WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Risk 40
Severity
6.5
First published (updated )

Open WebUI Open WebUIOpen WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Open WebUI Open WebUIOpen WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Risk 22
Severity
4.3
First published (updated )

Open WebUI Open WebUIOpen WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Risk 34
Severity
5.4
First published (updated )

Open WebUIOpen WebUI: Account enumeration via observable login timing discrepancy

Risk 27
Severity
5.3
First published (updated )

Open WebUI Open WebUIOpen WebUI: Stored web worker XSS via Pyodide

Risk 74
Severity
9
First published (updated )

pip/open-webuiOpen WebUI: Any authenticated user can read other users' private notes via Socket.IO

Risk 32
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/open-webuiOpen WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

Risk 46
Severity
6.3
First published (updated )

pip/open-webuiOpen WebUI: RAG ACL Bypass in Milvus Multitenancy Mode

Risk 38
Severity
6.5
First published (updated )

pip/open-webuiOpen WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects

Risk 44
Severity
7.7
First published (updated )

pip/open-webuiOpen WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

Risk 44
Severity
7.7
First published (updated )

pip/open-webuiOpen WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/open-webuiOpen WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

Risk 51
Severity
6.4
First published (updated )

pip/open-webuiOpen WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui

Risk 22
Severity
4.3
First published (updated )

pip/open-webuiOpen WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI

Risk 49
Severity
7.6
First published (updated )

pip/open-webuiOpen WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Risk 61
Severity
7.1
First published (updated )

pip/open-webuiOpen WebUI: Stored XSS in Mermaid Markdown Preview

Risk 61
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203