Classic298
26 exploits
Active since Dec 2025
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
CVSS 4.1
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
CVSS 5.4
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
CVSS 3.1
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
CVSS 4.3
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
CVSS 7.1
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
CVSS 8.2
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
CVSS 4.3
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
CVSS 6.5
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
CVSS 8.7
Open WebUI 0.9.6 to before 0.11.0 - Knowledge Search Regex Denial of Service
CVSS 6.5
Open WebUI 0.10.0 to before 0.11.0 - Folder Collaborator Chat Deletion
CVSS 8.1
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVSS 5.4
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVSS 3.5
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
CVSS 3.1
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
Open WebUI < 0.10.0 - Knowledge Base Write-Access Bypass
CVSS 4.3
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVSS 7.7
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVSS 4.3
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVSS 8.0
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVSS 5.4
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVSS 3.1
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVSS 4.3
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVSS 3.1
Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/web
CVSS 5.0
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVSS 8.1