Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4129
  • PyPI/open-webui
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange yesterday
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4117
  • PyPI/open-webui
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout yesterday
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-4126
  • PyPI/open-webui
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value yesterday
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4121
  • PyPI/open-webui
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle yesterday
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4127
  • PyPI/open-webui
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes yesterday
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-4124
  • PyPI/open-webui
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication yesterday
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-4128
  • PyPI/open-webui
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite yesterday
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-4125
  • PyPI/open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends yesterday
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4122
  • PyPI/open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint yesterday
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4123
  • PyPI/open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin yesterday
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-4120
  • PyPI/open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader yesterday
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-4118
  • PyPI/open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions yesterday
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-4115
  • PyPI/open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion yesterday
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-4116
  • PyPI/open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch yesterday
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-4119
  • PyPI/open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-wvm9-9g5j-623f
  • PyPI/open-webui
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)