CVE-2026-0765: (0Day) Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability
Open WebUI PIP installfrontmatterrequirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit this vulnerability.
The specific flaw exists within the installfrontmatterrequirements function.The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-28258.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0765?
CVE-2026-0765 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2026-0765?
To fix CVE-2026-0765, update the Open WebUI package to the latest version that addresses this vulnerability.
What does CVE-2026-0765 allow an attacker to do?
CVE-2026-0765 allows attackers to execute arbitrary code on the affected systems via command injection.
Which software is affected by CVE-2026-0765?
CVE-2026-0765 affects the Open WebUI software.
Is CVE-2026-0765 a known zero-day vulnerability?
Yes, CVE-2026-0765 is classified as a zero-day vulnerability.