CVE-2025-63391: High severity open-webui vulnerability
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63391?
CVE-2025-63391 is considered a high-severity vulnerability due to its potential for unauthorized access to sensitive configuration data.
How do I fix CVE-2025-63391?
To fix CVE-2025-63391, upgrade Open-WebUI to version 0.6.33 or later, which includes the necessary authentication and authorization controls.
What systems are affected by CVE-2025-63391?
CVE-2025-63391 affects all versions of Open-WebUI up to and including 0.6.32.
What type of vulnerability is CVE-2025-63391?
CVE-2025-63391 is an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive data.
What data can be exposed due to CVE-2025-63391?
CVE-2025-63391 can expose sensitive system configuration data that should only be accessible to authenticated users.