pypi

open-webui

View on pypi registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether open-webui is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.3
npm

CVE-2026-44721

open-webui Vulnerable to Stored XSS via Model Description

CRITICAL 9.1
PyPI

CVE-2026-44551

Open WebUI has an LDAP Empty Password Authentication Bypass

HIGH 8.5
PyPI

CVE-2025-65958

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

HIGH 7.5
PyPI

CVE-2024-12534

Open WebUI Uncontrolled Resource Consumption vulnerability

MEDIUM 4.3
PyPI

CVE-2024-7045

Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read

UNKNOWN
PyPI

CVE-2025-63681

open-webui is Vulnerable to Incorrect Access Control

MEDIUM 6.8
PyPI

CVE-2024-7044

Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload

HIGH 7.3
npm

CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

HIGH 7.5
PyPI

CVE-2024-7983

Open WebUI denial of service through endpoint for converting markdown

HIGH 8.1
PyPI

CVE-2024-8060

Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions

HIGH 7.5
PyPI

CVE-2024-8053

Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint

HIGH 7.5
PyPI

CVE-2024-12537

Open WebUI Uncontrolled Resource Consumption vulnerability

MEDIUM 6.5
PyPI

CVE-2024-7041

open-webui Insecure Direct Object Reference (IDOR) vulnerability

HIGH 7.5
PyPI

CVE-2024-7036

Open WebUI Uncontrolled Resource Consumption vulnerability

HIGH 7.6
PyPI

CVE-2024-7053

Open WebUI Vulnerable to a Session Fixation Attack

HIGH 8.1
PyPI

CVE-2024-7043

Open WebUI Allows Arbitrary File Reading and Deletion

HIGH 8.0
PyPI

CVE-2024-7806

Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability

MEDIUM 6.9
PyPI

CVE-2024-7035

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)

MEDIUM 4.3
PyPI

CVE-2024-7046

Open WebUI Allows Viewing of Admin Details

HIGH 8.4
PyPI

CVE-2024-7990

Open WebUI stored cross-site scripting (XSS) vulnerability

HIGH 8.7
npm

CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

MEDIUM 6.1
PyPI

CVE-2024-6706

Open WebUI Stored Cross-Site Scripting Vulnerability

HIGH 8.7
PyPI

CVE-2025-64495

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

HIGH 7.5
PyPI

CVE-2024-7036

Open WebUI Uncontrolled Resource Consumption vulnerability

HIGH 8.4
PyPI

CVE-2024-7990

Open WebUI stored cross-site scripting (XSS) vulnerability

MEDIUM 4.3
PyPI

CVE-2024-7046

Open WebUI Allows Viewing of Admin Details

HIGH 8.1
PyPI

CVE-2024-8060

Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions

HIGH 7.3
PyPI

CVE-2025-64496

Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events

HIGH 7.5
PyPI

CVE-2024-12537

Open WebUI Uncontrolled Resource Consumption vulnerability

HIGH 8.5
PyPI

CVE-2025-65958

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

MEDIUM 4.3
PyPI

CVE-2024-7045

Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read

HIGH 8.0
PyPI

CVE-2024-7806

Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability

HIGH 7.6
PyPI

CVE-2024-7053

Open WebUI Vulnerable to a Session Fixation Attack

MEDIUM 6.5
PyPI

CVE-2024-7037

open-webui allows writing and deleting arbitrary files

HIGH 7.5
PyPI

CVE-2024-12534

Open WebUI Uncontrolled Resource Consumption vulnerability

CRITICAL 9.1
PyPI

CVE-2026-44551

Open WebUI has an LDAP Empty Password Authentication Bypass

MEDIUM 5.3
PyPI

CVE-2026-54022

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

MEDIUM 6.3
PyPI

CVE-2026-54021

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

HIGH 7.7
PyPI

CVE-2026-54018

Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects

HIGH 7.7
PyPI

CVE-2026-54017

Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal

MEDIUM 6.5
PyPI

CVE-2026-54019

Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode

MEDIUM 4.3
PyPI

CVE-2026-54016

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

HIGH 7.6
PyPI

CVE-2026-54013

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

MEDIUM 4.3
PyPI

CVE-2026-54014

Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}

MEDIUM 6.4
PyPI

CVE-2026-54015

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

HIGH 8.7
PyPI

CVE-2026-54011

Open WebUI: Stored XSS in Mermaid Markdown Preview

HIGH 7.1
PyPI

CVE-2026-54012

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

MEDIUM 4.3
PyPI

CVE-2026-54006

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

MEDIUM 6.5
PyPI

CVE-2026-54009

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field

HIGH 8.3
PyPI

CVE-2026-54010

Open WebUI: Forged chat-file link allows cross-user file read and deletion

HIGH 8.5
PyPI

CVE-2026-54008

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

UNKNOWN
PyPI

CVE-2026-54007

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

MEDIUM 5.4
PyPI

CVE-2026-44564

Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO

HIGH 8.7
PyPI

CVE-2026-45315

Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

HIGH 7.1
PyPI

CVE-2026-45350

Open WebUI's chat completion API allows tool restrictions to be bypassed

HIGH 7.7
PyPI

CVE-2026-45338

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

MEDIUM 6.5
PyPI

CVE-2026-45666

Open WebUI has an Indirect Object Reference (IDOR) in user notes

MEDIUM 5.4
PyPI

CVE-2026-45365

Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

MEDIUM 6.5
PyPI

CVE-2026-45667

Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)

MEDIUM 6.5
PyPI

CVE-2026-45351

Open WebUI Exposes System Prompt to Regular User [Non-Admin]

MEDIUM 4.6
PyPI

CVE-2026-45317

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation

MEDIUM 4.3
PyPI

CVE-2026-45347

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

MEDIUM 5.4
PyPI

CVE-2026-45318

Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)

MEDIUM 6.5
PyPI

CVE-2026-45345

Open WebUI missing authorization check at the model update function - models from other users can be updated

MEDIUM 5.4
PyPI

CVE-2026-45299

Open WebUI has Stored Cross-Site Scripting In Profile Picture

HIGH 7.3
PyPI

CVE-2026-44567

Open WebUI has Improper Authorization Control

MEDIUM 6.1
PyPI

CVE-2026-45314

Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image

HIGH 7.7
PyPI

CVE-2026-45303

Open WebUI has stored XSS via the HTML renedering view

HIGH 8.1
PyPI

CVE-2026-45301

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

HIGH 7.3
PyPI

CVE-2026-44549

Open WebUI has stored XSS in Excel file preview

HIGH 7.1
PyPI

CVE-2026-44569

Open WebUI's Insecure Message Access Breaks Authorization

LOW 3.5
PyPI

CVE-2026-45316

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

MEDIUM 6.5
PyPI

CVE-2026-44571

Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission

HIGH 8.1
PyPI

CVE-2026-44565

Open WebUI Arbitrary File Write, Delete via Path Traversal

HIGH 8.3
PyPI

CVE-2026-44570

Open WebUI has inconsistent authorization controls within memories API

HIGH 7.3
PyPI

CVE-2026-44566

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

MEDIUM 4.3
PyPI

CVE-2026-45385

Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint

MEDIUM 6.5
PyPI

CVE-2026-44562

Open WebUI's Model Import Overwrites Any Model Without Ownership Check

MEDIUM 5.4
PyPI

CVE-2026-45396

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

HIGH 8.5
PyPI

CVE-2026-45401

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

HIGH 8.1
PyPI

CVE-2026-45402

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

MEDIUM 5.3
PyPI

CVE-2026-45397

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

MEDIUM 4.3
PyPI

CVE-2026-44557

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

MEDIUM 5.4
PyPI

CVE-2026-44563

Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

HIGH 7.1
PyPI

CVE-2026-44556

Open WebUI's responses passthrough endpoint lacks access control authorization

HIGH 8.5
PyPI

CVE-2026-45331

Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature

MEDIUM 5.4
PyPI

CVE-2026-44561

Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels

HIGH 8.8
PyPI

CVE-2026-45672

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

MEDIUM 4.3
PyPI

CVE-2026-45386

Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint

HIGH 7.5
PyPI

CVE-2026-45398

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls

HIGH 8.7
PyPI

CVE-2026-44552

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

HIGH 8.1
PyPI

CVE-2026-44553

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

HIGH 8.1
PyPI

CVE-2026-45675

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

HIGH 7.1
PyPI

CVE-2026-45349

Open WebUI has Broken Access Control for Completions API

MEDIUM 6.5
PyPI

CVE-2026-44560

Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search

MEDIUM 4.3
PyPI

CVE-2026-45387

Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

MEDIUM 5.0
PyPI

CVE-2026-44550

Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

HIGH 8.1
PyPI

CVE-2026-44554

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

HIGH 7.6
PyPI

CVE-2026-44555

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

HIGH 8.5
PyPI

CVE-2026-45400

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes