Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wvm9-9g5j-623f
  • PyPI/open-webui
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3g9q-v48f-hh9w
  • PyPI/open-webui
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout 10 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-v39v-59xw-j98g
  • PyPI/open-webui
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-8r35-5x5r-hv74
  • PyPI/open-webui
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-wjwr-xfp9-r66p
  • PyPI/open-webui
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-p78m-89r6-pgf7
  • PyPI/open-webui
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication 10 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-wpmr-8h3q-fwj7
  • PyPI/open-webui
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite 10 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-pcvc-8vrv-8q6w
  • PyPI/open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fmqh-xp37-5hr8
  • PyPI/open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-jmc6-2wr8-h3wj
  • PyPI/open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin 10 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-4v28-j6q3-5m4r
  • PyPI/open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader 10 Sep
  • Fix available
  • Severity - 7.7 (High)
GHSA-3pf7-q2g3-wj28
  • PyPI/open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-2724-6cpj-gf3v
  • PyPI/open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion 10 Sep
  • Fix available
  • Severity - 7.1 (High)
GHSA-34r3-9m95-vq73
  • PyPI/open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch 10 Sep
  • Fix available
  • Severity - 7.1 (High)
GHSA-4qg5-cxx4-g927
  • PyPI/open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3877
  • PyPI/open-webui
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)