Open WebUI Vulnerabilities

pip ML UI

AI Threat Alert tracks 169 known vulnerabilities in Open WebUI, 1 rated critical — an AI/ML ml ui in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
38
Risk Score
169
Total CVEs
1
Critical
pip
Ecosystem
Sep 10, 2026
Last CVE
83%
Patch Rate
5d
Avg Time to Patch
153,277 stars 22,431 forks 324 issues 3 dependents Last push Sep 26, 2026
View on GitHub

Known Vulnerabilities (169 total, page 7 of 7)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2024-7034 open-webui: path traversal allows arbitrary file write/RCE 6.5 Mar 20, 2025 HIGH CVE-2024-12534 open-webui: unauthenticated DoS via login payload flood 7.5 Mar 20, 2025 MEDIUM CVE-2024-7033 open-webui: path traversal allows file write and RCE 6.5 Mar 20, 2025 MEDIUM CVE-2024-7046 Open WebUI: missing authz leaks admin credentials 4.3 Mar 20, 2025 HIGH CVE-2024-7053 open-webui: XSS enables admin session hijack via chat 7.6 Mar 20, 2025 HIGH GHSA-w466-2wfc-8g58 open-webui: DoS via starlette memory exhaustion 7.5 Mar 20, 2025 HIGH GHSA-6wj5-5pgr-jwq8 open-webui: DoS via malformed multipart boundary 7.5 Mar 20, 2025 HIGH CVE-2024-7806 Open-WebUI: CSRF enables RCE via pipeline code injection 8.0 Mar 20, 2025 HIGH CVE-2024-7983 open-webui: unauthenticated DoS via markdown parser 7.5 Mar 20, 2025 HIGH CVE-2024-8053 Open-WebUI: unauthenticated PDF endpoint enables DoS 7.5 Mar 20, 2025 HIGH CVE-2024-8060 OpenWebUI: path traversal RCE via audio upload API 8.1 Mar 20, 2025 HIGH CVE-2024-7990 open-webui: Stored XSS enables admin session hijack 8.4 Mar 20, 2025 MEDIUM CVE-2024-7035 Open WebUI: CSRF wipes RAG DB and AI memories via GET 6.9 Mar 20, 2025 HIGH CVE-2024-7036 open-webui: unauthenticated DoS disables Admin panel 7.5 Mar 20, 2025 HIGH CVE-2025-64495 Open WebUI: XSS-to-RCE via malicious prompt injection 8.7 Nov 7, 2025 HIGH CVE-2025-64496 open-webui: Code Injection enables RCE 7.3 Nov 7, 2025 HIGH CVE-2025-65958 open-webui: SSRF allows internal network access 8.5 Dec 4, 2025 LOW CVE-2025-63681 open-webui: Access Control bypass enables privilege escalation -- Dec 4, 2025 HIGH CVE-2024-7959 Open-WebUI: SSRF via unchecked OpenAI URL leaks internal secrets 7.7 Mar 20, 2025

Showing 151–169 of 169

Frequently asked questions

What is Open WebUI?

Open WebUI is an AI/ML ml ui tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Open WebUI have?

Open WebUI has 169 known CVEs, 1 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Open WebUI distributed in?

Open WebUI is distributed via the pip ecosystem and categorized as ml ui.

Where does the Open WebUI vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Open WebUI?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Open WebUI in your stack

Get instant alerts when new vulnerabilities affect Open WebUI. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring