CVE-2025-15603

LOW

open-webui <=0.6.16 - Insufficient Randomness

Title source: llm
STIX 2.1

Description

A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

Scores

CVSS v3 3.7
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-310 CWE-330
Status published
Products (17)
n/a/open-webui 0.6.0
n/a/open-webui 0.6.1
n/a/open-webui 0.6.10
n/a/open-webui 0.6.11
n/a/open-webui 0.6.12
n/a/open-webui 0.6.13
n/a/open-webui 0.6.14
n/a/open-webui 0.6.15
n/a/open-webui 0.6.16
n/a/open-webui 0.6.2
... and 7 more
Published Mar 09, 2026
Tracked Since Mar 10, 2026