Open WebUI
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 54 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 16, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
Monitor Open WebUI in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.