Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45386 |
|
Vulnerability in open-webui (CVE-2026-45386)
vulnerability in open-webui (CVE-2026-45386). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/channels/create`. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2026-45385 |
|
Vulnerability in open-webui (CVE-2026-45385)
vulnerability in open-webui (CVE-2026-45385). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/channels/create`. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2026-45365 |
|
Vulnerability in open-webui (CVE-2026-45365)
vulnerability in open-webui (CVE-2026-45365). Risk of unauthorized operations or information disclosure. Exploitable via `POST /openai/chat/completions`. Mitigation: upgrade to `0.8.11` or later.
|
| CVE-2026-45351 |
|
Information Disclosure in open-webui (CVE-2026-45351)
vulnerability in open-webui (CVE-2026-45351). Confidential information can be exposed externally. Exploitable via `GET /api/models`. Mitigation: upgrade to `0.8.9` or later.
|
| CVE-2026-45350 |
|
Vulnerability in open-webui (CVE-2026-45350)
vulnerability in open-webui (CVE-2026-45350). Confidential information can be exposed externally. Exploitable via ``tool_id``. Mitigation: upgrade to `0.8.6` or later.
|
| CVE-2026-45349 |
|
Vulnerability in open-webui (CVE-2026-45349)
vulnerability in open-webui (CVE-2026-45349). Confidential information can be exposed externally. Exploitable via ``chat_completion``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45347 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45347)
SSRF in open-webui (CVE-2026-45347). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/utils/pdf`. Mitigation: upgrade to `0.5.11` or later.
|
| CVE-2026-45346 |
|
Vulnerability in open-webui (CVE-2026-45346)
vulnerability in open-webui (CVE-2026-45346). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.31` or later.
|
| CVE-2026-45345 |
|
Vulnerability in open-webui (CVE-2026-45345)
vulnerability in open-webui (CVE-2026-45345). Data can be tampered with by attackers. Exploitable via `POST /api/v1/models/model/update`. Mitigation: upgrade to `0.5.7` or later.
|
| CVE-2026-45339 |
|
Authorization Flaw in open-webu (CVE-2026-45339)
vulnerability in open-webu (CVE-2026-45339). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45338 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45338)
SSRF in open-webui (CVE-2026-45338). Confidential information can be exposed externally. Exploitable via ``picture``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45331 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45331)
SSRF in open-webui (CVE-2026-45331). Confidential information can be exposed externally. Exploitable via ``validators``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45317 |
|
Vulnerability in open-webui (CVE-2026-45317)
vulnerability in open-webui (CVE-2026-45317). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.3` or later.
|
| CVE-2026-45318 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-45318)
cross-site scripting in open-webui (CVE-2026-45318). Risk of unauthorized operations or information disclosure. Exploitable via ``fileOfficeHtml``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-45316 |
|
Authorization Flaw in open-webui (CVE-2026-45316)
vulnerability in open-webui (CVE-2026-45316). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/notes/{id}/pin`. Mitigation: upgrade to `0.9.3` or later.
|
| CVE-2026-45314 |
|
Vulnerability in open-webui (CVE-2026-45314)
vulnerability in open-webui (CVE-2026-45314). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/channels/webhooks/{webhook_id}/profile/image`. Mitigation: upgrade to `0.9.3` or later.
|
| CVE-2026-45315 |
|
Unrestricted File Upload in open-webui (CVE-2026-45315)
vulnerability in open-webui (CVE-2026-45315). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.3` or later.
|
| CVE-2026-45303 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-45303)
cross-site scripting in open-webui (CVE-2026-45303). Confidential information can be exposed externally. Exploitable via ``High``. Mitigation: upgrade to `0.6.5` or later.
|
| CVE-2026-45301 |
|
Vulnerability in open-webui (CVE-2026-45301)
vulnerability in open-webui (CVE-2026-45301). Confidential information can be exposed externally. Exploitable via ``user_id``. Mitigation: upgrade to `0.3.16` or later.
|
| CVE-2026-45299 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-45299)
cross-site scripting in open-webui (CVE-2026-45299). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/users/{user_id}/profile/image`. Mitigation: upgrade to `>= 0.8.0` or later.
|
| CVE-2026-44570 |
|
Vulnerability in open-webui (CVE-2026-44570)
vulnerability in open-webui (CVE-2026-44570). Confidential information can be exposed externally. Exploitable via `POST /api/v1/memories/query`. Mitigation: upgrade to `0.6.19` or later.
|
| CVE-2026-44571 |
|
Vulnerability in open-webui (CVE-2026-44571)
vulnerability in open-webui (CVE-2026-44571). Data can be tampered with by attackers. Exploitable via `POST /api/v1/channels/{channel_id}/messages/{message_id}/update`. Mitigation: upgrade to `0.8.6` or later.
|
| CVE-2026-44569 |
|
Vulnerability in open-webui (CVE-2026-44569)
vulnerability in open-webui (CVE-2026-44569). Data can be tampered with by attackers. Exploitable via ``message_id``. Mitigation: upgrade to `0.6.19` or later.
|
| CVE-2026-44565 |
|
Path Traversal in open-webui (CVE-2026-44565)
path traversal in open-webui (CVE-2026-44565). Data can be tampered with by attackers. Exploitable via ``DELETE_ME``. Mitigation: upgrade to `0.6.10` or later.
|
| CVE-2026-44566 |
|
Path Traversal in open-webui (CVE-2026-44566)
path traversal in open-webui (CVE-2026-44566). Risk of unauthorized operations or information disclosure. Exploitable via ``file``. Mitigation: upgrade to `0.1.124` or later.
|
| CVE-2026-44567 |
|
Vulnerability in open-webui (CVE-2026-44567)
vulnerability in open-webui (CVE-2026-44567). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auths/signup`. Mitigation: upgrade to `0.1.124` or later.
|
| CVE-2026-44549 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44549)
cross-site scripting in open-webui (CVE-2026-44549). Confidential information can be exposed externally. Exploitable via ``XLSX.utils.sheet_to_html``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-44568 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44568)
cross-site scripting in open-webui (CVE-2026-44568). Risk of unauthorized operations or information disclosure. Exploitable via ``AccountPending.svelte``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44560 |
|
Vulnerability in open-webui (CVE-2026-44560)
vulnerability in open-webui (CVE-2026-44560). Confidential information can be exposed externally. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44561 |
|
Authorization Flaw in open-webui (CVE-2026-44561)
vulnerability in open-webui (CVE-2026-44561). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/channels/{channel_id}/messages`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44564 |
|
Authorization Flaw in open-webui (CVE-2026-44564)
vulnerability in open-webui (CVE-2026-44564). Risk of unauthorized operations or information disclosure. Exploitable via ``read``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44563 |
|
Vulnerability in open-webui (CVE-2026-44563)
vulnerability in open-webui (CVE-2026-44563). Risk of unauthorized operations or information disclosure. Exploitable via `POST /ollama/api/generate`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44562 |
|
Vulnerability in open-webui (CVE-2026-44562)
vulnerability in open-webui (CVE-2026-44562). Data can be tampered with by attackers. Exploitable via `POST /api/v1/models/import`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44559 |
|
Vulnerability in open-webui (CVE-2026-44559)
vulnerability in open-webui (CVE-2026-44559). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/channels/{id}/members`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44557 |
|
Authorization Flaw in open-webui (CVE-2026-44557)
vulnerability in open-webui (CVE-2026-44557). Risk of unauthorized operations or information disclosure. Exploitable via `POST /query/doc`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44554 |
|
Vulnerability in open-webui (CVE-2026-44554)
vulnerability in open-webui (CVE-2026-44554). Data can be tampered with by attackers. Exploitable via `POST /api/v1/retrieval/process/web`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44558 |
|
Vulnerability in open-webui (CVE-2026-44558)
vulnerability in open-webui (CVE-2026-44558). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/channels/`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44556 |
|
Vulnerability in open-webui (CVE-2026-44556)
vulnerability in open-webui (CVE-2026-44556). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44555 |
|
Vulnerability in open-webui (CVE-2026-44555)
vulnerability in open-webui (CVE-2026-44555). Confidential information can be exposed externally. Exploitable via `POST /api/v1/models/create`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44552 |
|
Vulnerability in open-webui (CVE-2026-44552)
vulnerability in open-webui (CVE-2026-44552). Confidential information can be exposed externally. Exploitable via ``REDIS_KEY_PREFIX``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44553 |
|
Vulnerability in open-webui (CVE-2026-44553)
vulnerability in open-webui (CVE-2026-44553). Confidential information can be exposed externally. Exploitable via `POST /api/v1/users/{B_id}/update`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44550 |
|
Vulnerability in open-webui (CVE-2026-44550)
vulnerability in open-webui (CVE-2026-44550). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/users/search`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44551 |
|
Authentication Bypass in open-webui (CVE-2026-44551)
authentication bypass in open-webui (CVE-2026-44551). Confidential information can be exposed externally. Exploitable via `POST /api/v1/auths/ldap`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44721 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44721)
cross-site scripting in open-webui (CVE-2026-44721). Confidential information can be exposed externally. Exploitable via ``marked``. Mitigation: upgrade to `0.9.0` or later.
|