Open WebUI Vulnerabilities

pip ML UI

AI Threat Alert tracks 169 known vulnerabilities in Open WebUI, 1 rated critical — an AI/ML ml ui in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
38
Risk Score
169
Total CVEs
1
Critical
pip
Ecosystem
Sep 10, 2026
Last CVE
83%
Patch Rate
5d
Avg Time to Patch
153,277 stars 22,431 forks 324 issues 3 dependents Last push Sep 26, 2026
View on GitHub

Known Vulnerabilities (169 total, page 1 of 7)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-88006 Open WebUI: OAuth endpoint skips role revocation checks 6.5 Sep 10, 2026 MEDIUM CVE-2026-88005 Open WebUI: OAuth token exchange bypasses domain allowlist 6.5 Sep 10, 2026 HIGH CVE-2026-87998 Open WebUI: authZ flaw lets users kill shared KB configs 7.1 Sep 9, 2026 HIGH CVE-2026-87999 Open WebUI: SSRF leaks Azure platform channel 7.1 Sep 9, 2026 MEDIUM CVE-2026-87997 Open WebUI: folder auth bypass injects rogue chats 4.3 Sep 9, 2026 MEDIUM CVE-2026-87994 Open WebUI: channel authz gap allows message spoofing 4.3 Sep 9, 2026 HIGH CVE-2026-87016 Open WebUI: OAuth wildcard bug hijacks admin sessions 8.1 Sep 9, 2026 HIGH CVE-2026-87995 Open WebUI: XSS in terminal preview hijacks user accounts 8.7 Sep 9, 2026 HIGH CVE-2026-87996 Open WebUI: DNS rebinding SSRF exposes internal svcs 7.7 Sep 9, 2026 MEDIUM CVE-2026-87017 Open WebUI: KB metadata leaks across tenants in 11 backends 4.3 Sep 9, 2026 MEDIUM CVE-2026-87015 Open WebUI: session cookies leak to rogue tool server 6.8 Sep 9, 2026 HIGH CVE-2026-87011 Open WebUI: unauth DoS via OIDC logout handler 7.5 Sep 9, 2026 MEDIUM CVE-2026-87012 Open WebUI: type confusion suppresses all reminders 4.3 Sep 9, 2026 MEDIUM CVE-2026-87013 Open WebUI: authenticated DoS via folder cycle 4.3 Sep 9, 2026 MEDIUM CVE-2026-87014 Open WebUI: demoted admins keep socket access to all notes 6.5 Sep 9, 2026 MEDIUM CVE-2026-88002 open-webui: infinite-loop DoS crashes entire server 6.5 Sep 9, 2026 MEDIUM CVE-2026-88001 Open WebUI: SSRF via redirects reaches internal/metadata IPs 5.0 Sep 9, 2026 MEDIUM CVE-2026-88000 open-webui: malicious chat history causes DoS 6.5 Sep 9, 2026 HIGH CVE-2026-70486 Open WebUI: iframe sandbox bypass = account takeover 8.2 Aug 4, 2026 MEDIUM CVE-2026-70488 open-webui: broken authz lets users delete others' KB data 4.3 Aug 4, 2026 MEDIUM CVE-2026-70487 Open WebUI: IDOR leaks other users' RAG file content 5.3 Aug 4, 2026 MEDIUM CVE-2026-54020 Open WebUI: DNS-rebind SSRF bypasses URL check 6.3 Aug 4, 2026 MEDIUM CVE-2026-70489 Open WebUI: automation rule parsing freezes server 6.5 Aug 4, 2026 MEDIUM CVE-2026-70490 open-webui: terminal WebSocket bypasses role gate 6.3 Aug 4, 2026 MEDIUM CVE-2026-70491 open-webui: shared tool source leaks hardcoded API keys 6.5 Aug 4, 2026

Showing 1–25 of 169

Frequently asked questions

What is Open WebUI?

Open WebUI is an AI/ML ml ui tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Open WebUI have?

Open WebUI has 169 known CVEs, 1 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Open WebUI distributed in?

Open WebUI is distributed via the pip ecosystem and categorized as ml ui.

Where does the Open WebUI vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Open WebUI?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Open WebUI in your stack

Get instant alerts when new vulnerabilities affect Open WebUI. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring