CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange Exploitation status Not known exploited Fix YesAffected product O open-webui Published 09/10/2026 Severity Medium CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange Exploitation status Not confirmed Fix YesAffected product O open-webui Published 09/10/2026 Severity Medium CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history Exploitation status Not confirmed Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion Exploitation status Not known exploited Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions Exploitation status Not confirmed Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader Exploitation status Not known exploited Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends Exploitation status Not known exploited Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite Exploitation status Not confirmed Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87013Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle Exploitation status Public exploit Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87012Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value Exploitation status Not known exploited Fix YesAffected product O open-webui Published 09/09/2026 Severity Medium CVE-2026-87011Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout Exploitation status Not confirmed Fix YesAffected product O open-webui Published 09/09/2026 Severity High CVE-2026-59714Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids) Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/13/2026 Severity High CVE-2026-70494Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-70493Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70492Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-70491Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70490Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70489Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypass Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70488Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70487Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70486Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-70485Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-70484Open WebUI: Users denied the image-generation permission can still generate images via chat completions Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70483Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity Low CVE-2026-70482Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-70481Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages Exploitation status Not known exploited Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70480Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity Medium CVE-2026-70479Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader Exploitation status Public exploit Fix YesAffected product O open-webui Published 08/04/2026 Severity High CVE-2026-56400open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/15/2026 Severity Critical CVE-2026-56398Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/15/2026 Severity High CVE-2026-59221open-webui terminal proxy path traversal guard bypass via 9x encoded traversal Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity High CVE-2026-59225Open WebUI: Arena task endpoints can bypass underlying model access controls Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59224Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity High CVE-2026-59212Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59223Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59222Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59215Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Low CVE-2026-59213Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse) Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Low CVE-2026-59217Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB) Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59216Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity High CVE-2026-59219Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity High CVE-2026-59715Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave) Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Low CVE-2026-59220Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59226Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity Low CVE-2026-59227Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission Exploitation status Public exploit Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59218Open WebUI: Account enumeration via observable login timing discrepancy Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity Medium CVE-2026-59214Open WebUI: Stored web worker XSS via Pyodide Exploitation status Not known exploited Fix YesAffected product O open-webui Published 07/09/2026 Severity High CVE-2026-56399Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/web Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/30/2026 Severity Medium CVE-2026-54007Open WebUI: Cross-origin postMessage confirmation bypass via action:submit Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54006Open WebUI: Calendar event re-parenting allows writing events into another user's calendar Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54008Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54009Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54010Open WebUI: Forged chat-file link allows cross-user file read and deletion Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54011Open WebUI: Stored XSS in Mermaid Markdown Preview Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54012Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54013Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54014Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54015Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54016Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54018Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity High CVE-2026-54019Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54021Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter Exploitation status Not known exploited Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54022Open WebUI: Any authenticated user can read other users' private notes via Socket.IO Exploitation status Public exploit Fix YesAffected product O open-webui Published 06/23/2026 Severity Medium CVE-2026-54017Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal Exploitation status Public exploit Fix Not confirmed Affected product O open-webui Published 06/18/2026 Severity High CVE-2026-45338Open WebUI: SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py) Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-44549Open WebUI: Stored XSS in excel file preview Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45299Open WebUI: Stored Cross-Site Scripting In Profile Picture Exploitation status Not known exploited Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45665Open WebUI: Stored XSS in Banner Component via Improper Sanitization Order Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45667Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS) Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-44565Open WebUI: Open WebUI Arbitrary File Write, Delete via Path Traversal Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45314Open WebUI: XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45316Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access) Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Low CVE-2026-45317Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45318Open WebUI: Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify) Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45315Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-44571Open WebUI: Improper Authorization in Standard Channels Allows Message Updates with Read Permission Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45350Open WebUI: Chat completion API allows tool restrictions to be bypassed Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45303Open WebUI: Stored XSS via the HTML renedering view Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45301Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45345Open WebUI: Missing authorization check at the model update function - models from other users can be updated Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45346Open WebUI: Stored Cross-Site Scripting in SVG Renderer Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45347Open WebUI: Blind server side request forgery (SSRF) via the PDF generate function Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45351Open WebUI: Exposure of System Prompt to Regular User [Non-Admin] Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45666Open WebUI: Indirect Object Reference (IDOR) in user notes Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-45365Open WebUI: Authenticated users can bypass model access control via exposed query parameter Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity Medium CVE-2026-44570Open WebUI: Inconsistent authorization controls within memories API Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-44569Open WebUI: Insecure Message Access Breaks Authorization Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-44566Open WebUI: Arbitrary File Upload and Path Traversal Exploitation status Not known exploited Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-44567Open WebUI: Open WebUI Improper Authorization Control Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45672Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45400Open WebUI: Server-Side Request Forgery (SSRF) bypass in `validate_url` Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High CVE-2026-45402Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints Exploitation status Public exploit Fix YesAffected product O open-webui Published 05/15/2026 Severity High