Open WebUI is an open-source interface and orchestration layer for large language models and AI services that has become prominent in enterprise and research deployments, despite maintaining a narrowly scoped product line. The vendor's vulnerability profile concentrates in the single Open WebUI application and clusters around web application and authorization weaknesses—cross-site scripting, missing or bypassable authorization checks, and server-side request forgery—that are characteristic of user-facing applications handling authentication and untrusted user input. These weakness classes reflect the attack surface of a web-facing service that bridges user requests to backend AI models and external services, where input validation and access-control enforcement are critical to maintaining isolation between user sessions and preventing lateral movement. Defenders should monitor this vendor's releases closely given the sensitive nature of the data and model access it typically guards, and should treat authorization and input-handling fixes as high-priority in environments where the application sits ahead of production workloads. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwebui over time
Signals from CVEs in this vendor scope (134 CVEs).
134 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44551CRITICAL Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submi | May 15, 2026 | 9.1 | 47 | NO | YES |
CVE-2026-56400CRITICAL open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functio | Jul 15, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-0766HIGH Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati | Jan 23, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-56398CRITICAL Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension | Jul 15, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-59216CRITICAL Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to | Jul 9, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-59214CRITICAL Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, | Jul 9, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-54008HIGH Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls val | Jun 23, 2026 | 8.5 | 35 | NO | NO |
CVE-2026-44566CRITICAL Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derive | May 15, 2026 | 9.8 | 35 | NO | NO |
CVE-2025-64496HIGH Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct C | Nov 8, 2025 | 8.0 | 34 | NO | NO |
CVE-2026-59224HIGH Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/routers/terminals.py built the ws_terminal upstream URL fr | Jul 9, 2026 | 8.0 | 33 | NO | NO |
Signals from CVEs in this vendor scope (134 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwebui.
Media articles that mention a CVE ID that affects a product developed by Openwebui — matched by CVE ID, not by vendor name.