open-webui
PyPI106 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting open-webuipage 3 of 3
- CVE-2026-59215LOWCVSS 3.1EG 3.1✓ Fixed in 0.10.02026-07-09
vulnerable: 0.1.124 ... 0.9.6 (158 versions)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference a…
- CVE-2026-59216CRITICALCVSS 9.0EG 9.0✓ Fixed in 0.10.02026-07-09
vulnerable: 0.1.124 ... 0.9.6 (158 versions)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the s…
- CVE-2026-59221HIGHCVSS 7.7EG 7.7✓ Fixed in 0.10.02026-07-09
vulnerable: 0.9.6
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times per…
- CVE-2026-59223MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.10.02026-07-09
vulnerable: 0.1.124 ... 0.9.6 (158 versions)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_LIST matching compared configured host entries against URL strings and non-label-boundary suffixes, allowing path-based…
- CVE-2026-59226MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.10.02026-07-09
vulnerable: 0.9.0 ... 0.9.6 (7 versions)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking that they were still active or still had features.automation…
- CVE-2026-59715MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.10.02026-07-09
vulnerable: 0.6.16 ... 0.9.6 (51 versions)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Socket.IO server is configured with always_connect=True. The ydoc:awareness:update and ydoc:document:leave Socket.IO handl…
Check whether open-webui is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for open-webui CVEs against the assets you own.
Start Free Scan →