Any authenticated user can reach internal services via DNS rebinding on server-side URL fetches
Open WebUI security advisories
All 128 advisories Open WebUI has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 128125 carry a CVE
- critical
- 1
- high
- 61
- medium
- 59
- low
- 7
- Fix in the archive
- 116of 128 matched to a release
- Oldest
- 16 Apr 20242.4 years ago
12 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productCross-user file content disclosure via request-scoped direct model knowledge metadata
Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Users denied the image-generation permission can still generate images via chat completions
Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Tool source code disclosed to read-only users via the tool list and get endpoints
Any authenticated user can cancel another user's chat generation via the chat delete endpoint
A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Any member with write access to a standard channel can edit or delete other members' messages
Instance-wide stall via automation recurrence rules that force multi-second parsing
Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Account takeover via OAuth token exchange accepting tokens issued to any client
Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
/api/v1/channels/{id}/members exposes full user model including sensitive credentials
`WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Private channel messages can be disclosed through cross-channel thread parent_id binding
Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Model meta.knowledge read-only file access can be upgraded to file write/delete
Arena task endpoints can bypass underlying model access controls
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
Account enumeration via observable login timing discrepancy
Same-origin Pyodide code execution allows server-side RCE via a shared chat
ReDoS in skill-mention regexes causes whole-instance DoS on default config
POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Scheduled automations continue after pending-user deactivation and stored model ACL revocation
SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
Path traversal / SSRF in terminal server proxy via encoded path traversal
Any authenticated user can read other users' private notes via Socket.IO
Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Cross-origin postMessage confirmation bypass via action:submit
Stored XSS in Mermaid Markdown Preview
IDOR: Calendar event re-parenting allows writing events into another user's calendar
Cross-user file disclosure via /api/chat/completions image_url field
Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Stored XSS to Account Takeover via Model Profile Images in Open WebUI
RAG ACL Bypass in Milvus Multitenancy Mode
Forged chat-file link allows cross-user file read and deletion
Forged model meta.knowledge allows cross-user file read and deletion
Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Indirect Object Reference (IDOR) in user notes
Stored XSS in Banner Component via Improper Sanitization Order
Unauthenticated endpoint can trigger embedding generation (cost/DoS)
shared-chat branch ignores access_type, allowing unauthorized file deletion
Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Server-Side Request Forgery (SSRF) bypass in `validate_url`
SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
IDOR: Retrieval API Bypasses Knowledge Base Access Controls
An IDOR vulnerability exists in the update_message_by_id API endpoint
An IDOR vulnerability exists in the pin_channel_message API endpoint
Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
Unauthenticated RAG Configuration Disclosure
Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Full SSRF Vulnerability in the RAG Web Search Feature
Missing authorization check at the model update function - models from other users can be updated
Blind server side request forgery (SSRF) via the PDF generate function
Stored Cross-Site Scripting in SVG Renderer
Broken Access Control for Completions API
Exposure of System Prompt to Regular User [Non-Admin]
Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Chat completion API allows tool restrictions to be bypassed
API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
Stored XSS via the HTML renedering view
Stored Cross-Site Scripting In Profile Picture
KL-CAN-2024-002
KL-CAN-2024-004: Open WebUI Improper Authorization Control
KL-CAN-2024-005: Open WebUI Arbitrary File Write, Delete via Path Traversal
GitHub Security Lab (GHSL) Vulnerability Report, open-webui: GHSL-2024-174, GHSL-2024-175
Insecure Message Access Breaks Authorization
Inconsistent authorization controls within memories API
Full SSRF with user role on endpoint /api/v1/retrieval/process/web via location redirect
Stored XSS in excel file preview
Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
responses passthrough endpoint lacks access control authorization
Deactivated Channel Members Retain Full Access to Group/DM Channels
Read-Only Users Can Modify Collaborative Documents via Socket.IO
Missing Access Check on Channel Members Endpoint for Standard Channels
Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Model Import Overwrites Any Model Without Ownership Check
Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
LDAP Empty Password Authentication Bypass
Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Channel Access Grants Bypass filter_allowed_access_grants
Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Base Model Routing Bypasses Access Control via Model Chaining
Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Stored XSS via Model Description
Blind Server Side Request Forgery in Image Edit Functionality
Broken Access Control in Open WebUI Tool Valves
Path Traversal (CWE-22) in `POST /api/v1/audio/transcriptions`
Insecure Direct Object Reference (IDOR) allows access to other users' memories
process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite
Unauthorized deletion of knowledge files
Stored XSS via iFrame embeds in response messages
Stored XSS via iFrame in citations model
Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
Stored DOM XSS via Note 'Download PDF'
External Model Server (Direct Connections) Code Injection via SSE Events
Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Limited stored XSS vila uploaded html file
Server-side request forgery in utils.py