Dependency scanning
Check whether open-webui is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-44721
open-webui Vulnerable to Stored XSS via Model Description
CVE-2026-44551
Open WebUI has an LDAP Empty Password Authentication Bypass
CVE-2025-65958
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2024-12534
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7045
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2025-63681
open-webui is Vulnerable to Incorrect Access Control
CVE-2024-7044
Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
CVE-2025-64496
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2024-7983
Open WebUI denial of service through endpoint for converting markdown
CVE-2024-8060
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
CVE-2024-8053
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
CVE-2024-12537
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7041
open-webui Insecure Direct Object Reference (IDOR) vulnerability
CVE-2024-7036
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7053
Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7043
Open WebUI Allows Arbitrary File Reading and Deletion
CVE-2024-7806
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2024-7035
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2024-7046
Open WebUI Allows Viewing of Admin Details
CVE-2024-7990
Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2025-64495
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2024-6706
Open WebUI Stored Cross-Site Scripting Vulnerability
CVE-2025-64495
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2024-7036
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-7990
Open WebUI stored cross-site scripting (XSS) vulnerability
CVE-2024-7046
Open WebUI Allows Viewing of Admin Details
CVE-2024-8060
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
CVE-2025-64496
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2024-12537
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2025-65958
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
CVE-2024-7045
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
CVE-2024-7806
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2024-7053
Open WebUI Vulnerable to a Session Fixation Attack
CVE-2024-7037
open-webui allows writing and deleting arbitrary files
CVE-2024-12534
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2026-44551
Open WebUI has an LDAP Empty Password Authentication Bypass
CVE-2026-54022
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-54021
Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
CVE-2026-54018
Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
CVE-2026-54017
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
CVE-2026-54019
Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-54016
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
CVE-2026-54013
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-54014
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
CVE-2026-54015
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
CVE-2026-54011
Open WebUI: Stored XSS in Mermaid Markdown Preview
CVE-2026-54012
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54006
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
CVE-2026-54009
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
CVE-2026-54010
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54008
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
CVE-2026-54007
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-44564
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
CVE-2026-45315
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
CVE-2026-45350
Open WebUI's chat completion API allows tool restrictions to be bypassed
CVE-2026-45338
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
CVE-2026-45666
Open WebUI has an Indirect Object Reference (IDOR) in user notes
CVE-2026-45365
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
CVE-2026-45667
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
CVE-2026-45351
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
CVE-2026-45317
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVE-2026-45347
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
CVE-2026-45318
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
CVE-2026-45345
Open WebUI missing authorization check at the model update function - models from other users can be updated
CVE-2026-45299
Open WebUI has Stored Cross-Site Scripting In Profile Picture
CVE-2026-44567
Open WebUI has Improper Authorization Control
CVE-2026-45314
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
CVE-2026-45303
Open WebUI has stored XSS via the HTML renedering view
CVE-2026-45301
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
CVE-2026-44549
Open WebUI has stored XSS in Excel file preview
CVE-2026-44569
Open WebUI's Insecure Message Access Breaks Authorization
CVE-2026-45316
Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
CVE-2026-44571
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVE-2026-44565
Open WebUI Arbitrary File Write, Delete via Path Traversal
CVE-2026-44570
Open WebUI has inconsistent authorization controls within memories API
CVE-2026-44566
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-45385
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
CVE-2026-44562
Open WebUI's Model Import Overwrites Any Model Without Ownership Check
CVE-2026-45396
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
CVE-2026-45401
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
CVE-2026-45402
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
CVE-2026-45397
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
CVE-2026-44557
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
CVE-2026-44563
Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
CVE-2026-44556
Open WebUI's responses passthrough endpoint lacks access control authorization
CVE-2026-45331
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
CVE-2026-44561
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
CVE-2026-45672
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVE-2026-45386
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
CVE-2026-45398
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
CVE-2026-44552
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVE-2026-44553
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVE-2026-45675
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVE-2026-45349
Open WebUI has Broken Access Control for Completions API
CVE-2026-44560
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
CVE-2026-45387
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
CVE-2026-44550
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
CVE-2026-44554
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVE-2026-44555
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
CVE-2026-45400
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes