CVE-2026-0765: (0Day) Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0765
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit this vulnerability. The specific flaw exists within the installfrontmatterrequirements function.The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0765?
CVE-2026-0765 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2026-0765?
To fix CVE-2026-0765, update the Open WebUI package to the latest version that addresses this vulnerability.
What does CVE-2026-0765 allow an attacker to do?
CVE-2026-0765 allows attackers to execute arbitrary code on the affected systems via command injection.
Which software is affected by CVE-2026-0765?
CVE-2026-0765 affects the Open WebUI software.
Is CVE-2026-0765 a known zero-day vulnerability?
Yes, CVE-2026-0765 is classified as a zero-day vulnerability.