openwebui
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 174 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 16, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
Monitor openwebui in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.