Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3638
  • PyPI/open-webui
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder 10 Aug
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3637
  • PyPI/open-webui
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically 10 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3650
  • PyPI/open-webui
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages 10 Aug
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3639
  • PyPI/open-webui
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints 10 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3642
  • PyPI/open-webui
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check 10 Aug
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-3644
  • PyPI/open-webui
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing 10 Aug
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3647
  • PyPI/open-webui
Open WebUI: DNS Rebinding SSRF Bypass 10 Aug
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-3643
  • PyPI/open-webui
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata 10 Aug
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3648
  • PyPI/open-webui
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup 10 Aug
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3641
  • PyPI/open-webui
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin 10 Aug
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-3645
  • PyPI/open-webui
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs 10 Aug
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3646
  • PyPI/open-webui
Open WebUI: Users denied the image-generation permission can still generate images via chat completions 10 Aug
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3651
  • PyPI/open-webui
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering 10 Aug
  • Fix available
  • Severity - 4.1 (Medium)
PYSEC-2026-3640
  • PyPI/open-webui
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint 10 Aug
  • Fix available
  • Severity - 3.1 (Low)
PYSEC-2026-3652
  • PyPI/open-webui
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client 10 Aug
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3649
  • PyPI/open-webui
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages 10 Aug
  • Fix available
  • Severity - 5.4 (Medium)