{"data":{"ecosystem":"pypi","name":"open-webui","url":"https://aisecwatch.com/packages/pypi/open-webui","latestVersion":"0.11.4","firstReleaseAt":"2024-05-20T08:24:22.850Z","repository":null,"llm":{"exposure":"direct","depth":0,"integratedAt":"2024-05-20T08:24:22.850Z","integratedVersion":"0.1.124","sdks":["anthropic","chromadb","huggingface","langchain","mcp","milvus","openai","pgvector","pinecone","qdrant","weaviate"],"path":[]},"authority":{"profile":["browser","filesystem","http","mcp_tools"],"fromDependencies":["pypi:aiofiles","pypi:aiohttp","pypi:httpx","pypi:mcp","pypi:playwright","pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"accelerate","versionSpec":"==1.13.0","scope":"runtime"},{"ecosystem":"pypi","name":"anthropic","versionSpec":"==0.86.0","scope":"runtime"},{"ecosystem":"pypi","name":"chromadb","versionSpec":"==1.5.9","scope":"runtime"},{"ecosystem":"pypi","name":"colbert-ai","versionSpec":"==0.2.22","scope":"extra:all"},{"ecosystem":"pypi","name":"ddgs","versionSpec":"==9.14.4","scope":"runtime"},{"ecosystem":"pypi","name":"faster-whisper","versionSpec":"==1.2.1","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-classic","versionSpec":"==1.0.7","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":"==1.4.8","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-text-splitters","versionSpec":"==1.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"mcp","versionSpec":"==1.27.2","scope":"runtime"},{"ecosystem":"pypi","name":"openai","versionSpec":"==2.29.0","scope":"runtime"},{"ecosystem":"pypi","name":"pgvector","versionSpec":"==0.4.2","scope":"extra:all"},{"ecosystem":"pypi","name":"pinecone","versionSpec":"==6.0.2","scope":"extra:all"},{"ecosystem":"pypi","name":"pymilvus","versionSpec":"==2.6.14","scope":"extra:all"},{"ecosystem":"pypi","name":"qdrant-client","versionSpec":"==1.18.0","scope":"extra:all"},{"ecosystem":"pypi","name":"sentence-transformers","versionSpec":"==5.5.1","scope":"runtime"},{"ecosystem":"pypi","name":"transformers","versionSpec":"==5.5.4","scope":"runtime"},{"ecosystem":"pypi","name":"unstructured","versionSpec":"==0.22.31","scope":"extra:all"},{"ecosystem":"pypi","name":"weaviate-client","versionSpec":"==4.20.3","scope":"extra:all"},{"ecosystem":"pypi","name":"aiocache","versionSpec":"==0.12.3","scope":"runtime"},{"ecosystem":"pypi","name":"aiodns","versionSpec":"==3.6.1","scope":"runtime"},{"ecosystem":"pypi","name":"aiofiles","versionSpec":"==25.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"==3.13.5","scope":"runtime"},{"ecosystem":"pypi","name":"aiosqlite","versionSpec":"==0.22.1","scope":"runtime"},{"ecosystem":"pypi","name":"alembic","versionSpec":"==1.18.4","scope":"runtime"},{"ecosystem":"pypi","name":"argon2-cffi","versionSpec":"==25.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"asgiref","versionSpec":"==3.11.1","scope":"runtime"},{"ecosystem":"pypi","name":"authlib","versionSpec":"==1.7.2","scope":"runtime"},{"ecosystem":"pypi","name":"azure-ai-documentintelligence","versionSpec":"==1.0.2","scope":"runtime"},{"ecosystem":"pypi","name":"azure-identity","versionSpec":"==1.25.3","scope":"runtime"},{"ecosystem":"pypi","name":"azure-search-documents","versionSpec":"==12.0.0","scope":"extra:all"},{"ecosystem":"pypi","name":"azure-storage-blob","versionSpec":"==12.29.0","scope":"runtime"},{"ecosystem":"pypi","name":"bcrypt","versionSpec":"==5.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"beautifulsoup4","versionSpec":"==4.14.3","scope":"runtime"},{"ecosystem":"pypi","name":"black","versionSpec":"==26.5.1","scope":"runtime"},{"ecosystem":"pypi","name":"boto3","versionSpec":"==1.42.62","scope":"runtime"},{"ecosystem":"pypi","name":"brotli","versionSpec":"==1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"brotlicffi","versionSpec":"==1.2.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"chardet","versionSpec":"==7.4.3","scope":"runtime"},{"ecosystem":"pypi","name":"cryptography","versionSpec":"==48.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"docx2txt","versionSpec":"==0.9","scope":"runtime"},{"ecosystem":"pypi","name":"einops","versionSpec":"==0.8.2","scope":"runtime"},{"ecosystem":"pypi","name":"elasticsearch","versionSpec":"==9.4.1","scope":"extra:all"},{"ecosystem":"pypi","name":"fake-useragent","versionSpec":"==2.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"fastapi","versionSpec":"==0.136.3","scope":"runtime"},{"ecosystem":"pypi","name":"ftfy","versionSpec":"==6.3.1","scope":"runtime"},{"ecosystem":"pypi","name":"googleapis-common-protos","versionSpec":"==1.75.0","scope":"runtime"},{"ecosystem":"pypi","name":"google-cloud-storage","versionSpec":"==3.9.0","scope":"runtime"},{"ecosystem":"pypi","name":"google-re2","versionSpec":"==1.1.20251105","scope":"runtime"},{"ecosystem":"pypi","name":"hiredis","versionSpec":"==3.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":"==0.28.1","scope":"runtime"},{"ecosystem":"pypi","name":"itsdangerous","versionSpec":"==2.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"joserfc","versionSpec":"==1.7.4","scope":"runtime"},{"ecosystem":"pypi","name":"ldap3","versionSpec":"==2.9.1","scope":"runtime"},{"ecosystem":"pypi","name":"loguru","versionSpec":"==0.7.3","scope":"runtime"},{"ecosystem":"pypi","name":"lxml","versionSpec":"==6.1.1","scope":"runtime"},{"ecosystem":"pypi","name":"mariadb","versionSpec":"==1.1.14","scope":"extra:mariadb"},{"ecosystem":"pypi","name":"markdown","versionSpec":"==3.10.2","scope":"runtime"},{"ecosystem":"pypi","name":"msoffcrypto-tool","versionSpec":"==6.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"onnxruntime","versionSpec":"==1.26.0","scope":"runtime"},{"ecosystem":"pypi","name":"opencv-python-headless","versionSpec":"==4.13.0.92","scope":"runtime"},{"ecosystem":"pypi","name":"openpyxl","versionSpec":"==3.1.5","scope":"runtime"},{"ecosystem":"pypi","name":"opensearch-py","versionSpec":"==3.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"oracledb","versionSpec":"==3.4.2","scope":"extra:all"},{"ecosystem":"pypi","name":"orjson","versionSpec":"==3.11.9","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":"==3.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":"==12.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"playwright","versionSpec":"==1.60.0","scope":"extra:all"},{"ecosystem":"pypi","name":"psutil","versionSpec":"==7.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"psycopg","versionSpec":"==3.3.4","scope":"runtime"},{"ecosystem":"pypi","name":"psycopg2-binary","versionSpec":"==2.9.12","scope":"extra:all"},{"ecosystem":"pypi","name":"pyarrow","versionSpec":"==20.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"pycrdt","versionSpec":"==0.13.1","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"==2.13.4","scope":"runtime"},{"ecosystem":"pypi","name":"pydub","versionSpec":"==0.25.1","scope":"runtime"},{"ecosystem":"pypi","name":"pyjwt","versionSpec":"==2.13.0","scope":"runtime"},{"ecosystem":"pypi","name":"pymysql","versionSpec":"==1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"pypandoc","versionSpec":"==1.17","scope":"runtime"},{"ecosystem":"pypi","name":"pypdf","versionSpec":"==6.7.5","scope":"runtime"},{"ecosystem":"pypi","name":"python-docx","versionSpec":"==1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"python-mimeparse","versionSpec":"==2.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":"==0.0.32","scope":"runtime"},{"ecosystem":"pypi","name":"python-pptx","versionSpec":"==1.0.2","scope":"runtime"},{"ecosystem":"pypi","name":"python-socketio","versionSpec":"==5.16.2","scope":"runtime"},{"ecosystem":"pypi","name":"pytz","versionSpec":"==2026.2","scope":"runtime"},{"ecosystem":"pypi","name":"pyxlsb","versionSpec":"==1.0.10","scope":"runtime"},{"ecosystem":"pypi","name":"rank-bm25","versionSpec":"==0.2.2","scope":"runtime"},{"ecosystem":"pypi","name":"rapidocr","versionSpec":"==3.9.2","scope":"runtime"},{"ecosystem":"pypi","name":"redis","versionSpec":"==8.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"regex","versionSpec":"==2026.5.9","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"==2.34.2","scope":"runtime"},{"ecosystem":"pypi","name":"sentencepiece","versionSpec":"==0.2.1","scope":"runtime"},{"ecosystem":"pypi","name":"soundfile","versionSpec":"==0.13.1","scope":"runtime"},{"ecosystem":"pypi","name":"sqlalchemy","versionSpec":"==2.0.50","scope":"runtime"},{"ecosystem":"pypi","name":"starlette-compress","versionSpec":"==1.7.1","scope":"runtime"},{"ecosystem":"pypi","name":"starsessions","versionSpec":"==2.2.1","scope":"runtime"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":"==0.13.0","scope":"runtime"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":"==0.51.0","scope":"runtime"},{"ecosystem":"pypi","name":"validators","versionSpec":"==0.35.0","scope":"runtime"},{"ecosystem":"pypi","name":"xlrd","versionSpec":"==2.0.2","scope":"runtime"},{"ecosystem":"pypi","name":"youtube-transcript-api","versionSpec":"==1.2.4","scope":"runtime"}],"advisories":[{"id":"78fc15c1-2b8e-404a-af59-aeab42de5617","url":"https://aisecwatch.com/issues/78fc15c1-2b8e-404a-af59-aeab42de5617","cveId":"CVE-2026-87994","title":"GHSA-fmqh-xp37-5hr8: Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint","headline":null,"severity":"medium","publishedAt":"2026-09-10T15:10:29.000Z","affected":["open-webui@>= 0.9.5, < 0.11.1 (fixed: 0.11.1)"],"epssScore":0.00372},{"id":"c2150cdb-8b95-467b-97a8-4dbb5112d5eb","url":"https://aisecwatch.com/issues/c2150cdb-8b95-467b-97a8-4dbb5112d5eb","cveId":"CVE-2026-59213","title":"GHSA-3wp3-xxj9-5jqq: Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)","headline":null,"severity":"low","publishedAt":"2026-07-24T17:03:21.000Z","affected":["open-webui@>= 0.6.27, < 0.10.0 (fixed: 0.10.0)"],"epssScore":0.00373},{"id":"ff21f0af-9fab-4ddc-ac36-46e312dad2f0","url":"https://aisecwatch.com/issues/ff21f0af-9fab-4ddc-ac36-46e312dad2f0","cveId":"CVE-2026-59715","title":"GHSA-gmfw-g93r-vg53: Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)","headline":null,"severity":"low","publishedAt":"2026-07-24T16:59:44.000Z","affected":["open-webui@>= 0.6.16, < 0.10.0 (fixed: 0.10.0)"],"epssScore":0.00362},{"id":"8a63a3a0-3f3d-42d6-9439-52724062c16e","url":"https://aisecwatch.com/issues/8a63a3a0-3f3d-42d6-9439-52724062c16e","cveId":"CVE-2026-59227","title":"GHSA-rqj7-6wrp-6g2g: Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission","headline":null,"severity":"medium","publishedAt":"2026-07-24T16:58:48.000Z","affected":["open-webui@>= 0.8.11, < 0.10.0 (fixed: 0.10.0)"],"epssScore":0.0042},{"id":"aef24f01-fa83-4ef2-818c-64c40ce8a4b8","url":"https://aisecwatch.com/issues/aef24f01-fa83-4ef2-818c-64c40ce8a4b8","cveId":"CVE-2026-54021","title":"CVE-2026-54021: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6…","headline":"Open WebUI Ollama proxy routes let users reach unauthorized backends via url_idx","severity":"medium","publishedAt":"2026-06-23T18:18:07.370Z","affected":["open-webui@<= 0.9.5 (fixed: 0.9.6)"],"epssScore":0.00283},{"id":"eb9f38c3-8f4e-4e1c-baac-e5da4542d27a","url":"https://aisecwatch.com/issues/eb9f38c3-8f4e-4e1c-baac-e5da4542d27a","cveId":"CVE-2026-54019","title":"CVE-2026-54019: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open…","headline":"Open WebUI collection ACL bypass through Milvus multitenancy expression","severity":"medium","publishedAt":"2026-06-23T18:18:07.230Z","affected":["open-webui@<= 0.9.5 (fixed: 0.9.6)"],"epssScore":0.00386},{"id":"3972b392-736f-409c-983c-737869f2ecc8","url":"https://aisecwatch.com/issues/3972b392-736f-409c-983c-737869f2ecc8","cveId":"CVE-2026-54009","title":"GHSA-wch8-mhj5-9frg: Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field","headline":null,"severity":"medium","publishedAt":"2026-06-17T14:11:44.000Z","affected":["open-webui@<= 0.9.5 (fixed: 0.9.6)"],"epssScore":0.00382},{"id":"0ab955cd-a629-4c08-b3df-06fed6e16ca3","url":"https://aisecwatch.com/issues/0ab955cd-a629-4c08-b3df-06fed6e16ca3","cveId":"CVE-2026-45401","title":"CVE-2026-45401: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the…","headline":null,"severity":"high","publishedAt":"2026-05-15T21:16:38.140Z","affected":["open-webui@<= 0.9.4 (fixed: 0.9.5)"],"epssScore":0.00326},{"id":"8ec5bafb-79b8-4536-a589-807c217927f0","url":"https://aisecwatch.com/issues/8ec5bafb-79b8-4536-a589-807c217927f0","cveId":"CVE-2026-44563","title":"CVE-2026-44563: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the…","headline":"Open WebUI model access bypass in Ollama proxy endpoints","severity":"medium","publishedAt":"2026-05-15T20:16:48.000Z","affected":["open-webui@<= 0.8.12 (fixed: 0.9.0)"],"epssScore":0.00343},{"id":"fdd359ff-1a08-4ec1-8437-048defa9becb","url":"https://aisecwatch.com/issues/fdd359ff-1a08-4ec1-8437-048defa9becb","cveId":"CVE-2026-44556","title":"CVE-2026-44556: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the…","headline":"Open WebUI access control bypass in OpenAI /responses endpoint","severity":"high","publishedAt":"2026-05-15T20:16:47.097Z","affected":["open-webui@<= 0.8.12 (fixed: 0.9.0)"],"epssScore":0.00371},{"id":"783bd645-9b40-473a-a0f1-319ea4636722","url":"https://aisecwatch.com/issues/783bd645-9b40-473a-a0f1-319ea4636722","cveId":"CVE-2026-45675","title":"GHSA-h3ww-q6xx-w7x3: Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts","headline":null,"severity":"high","publishedAt":"2026-05-14T20:28:46.000Z","affected":["open-webui@<= 0.8.12 (fixed: 0.9.0)"],"epssScore":0.00505},{"id":"0b59d05e-70b2-46e6-9c00-c6c066a70fda","url":"https://aisecwatch.com/issues/0b59d05e-70b2-46e6-9c00-c6c066a70fda","cveId":"CVE-2026-45671","title":"GHSA-26g9-27vm-x3q8: Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion","headline":null,"severity":"high","publishedAt":"2026-05-14T20:28:34.000Z","affected":["open-webui@<= 0.8.12 (fixed: 0.9.0)"],"epssScore":0.00393},{"id":"2f99c8fe-d244-4acc-9e9d-169f8b8e38f2","url":"https://aisecwatch.com/issues/2f99c8fe-d244-4acc-9e9d-169f8b8e38f2","cveId":"CVE-2026-45667","title":"GHSA-m69w-p7m4-585j: Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)","headline":null,"severity":"medium","publishedAt":"2026-05-14T20:28:02.000Z","affected":["open-webui@<= 0.7.2 (fixed: 0.8.0)"],"epssScore":0.00433},{"id":"11613dd4-9487-4828-bb68-4b0e0798b88a","url":"https://aisecwatch.com/issues/11613dd4-9487-4828-bb68-4b0e0798b88a","cveId":"CVE-2026-45402","title":"GHSA-r472-mw7m-967f: Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints","headline":null,"severity":"high","publishedAt":"2026-05-14T20:27:35.000Z","affected":["open-webui@<= 0.9.4 (fixed: 0.9.5)"],"epssScore":0.00393},{"id":"5b8d7e03-844b-4ac2-981f-a24a48bec836","url":"https://aisecwatch.com/issues/5b8d7e03-844b-4ac2-981f-a24a48bec836","cveId":"CVE-2026-45398","title":"GHSA-4g37-7p2c-38r9: Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls","headline":null,"severity":"high","publishedAt":"2026-05-14T20:26:42.000Z","affected":["open-webui@<= 0.9.4 (fixed: 0.9.5)"],"epssScore":0.00489},{"id":"01570547-4bcf-4f29-b1a7-c823c05c4a42","url":"https://aisecwatch.com/issues/01570547-4bcf-4f29-b1a7-c823c05c4a42","cveId":"CVE-2026-45397","title":"GHSA-65pg-qhhw-mxwg: Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure","headline":null,"severity":"medium","publishedAt":"2026-05-14T20:26:34.000Z","affected":["open-webui@< 0.9.5 (fixed: 0.9.5)"],"epssScore":0.00808},{"id":"6c56e77c-471b-4149-86fa-be4c9346ca0c","url":"https://aisecwatch.com/issues/6c56e77c-471b-4149-86fa-be4c9346ca0c","cveId":"CVE-2026-45365","title":"GHSA-v6qf-75pr-p96m: Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]","headline":null,"severity":"medium","publishedAt":"2026-05-14T20:25:24.000Z","affected":["open-webui@<= 0.8.10 (fixed: 0.8.11)"],"epssScore":0.00267},{"id":"dca77fdc-e9dc-4504-9548-a720dd4d8cec","url":"https://aisecwatch.com/issues/dca77fdc-e9dc-4504-9548-a720dd4d8cec","cveId":"CVE-2026-45351","title":"GHSA-jh9g-8jqw-m2qx: Open WebUI Exposes System Prompt to Regular User [Non-Admin]","headline":null,"severity":"medium","publishedAt":"2026-05-14T20:25:04.000Z","affected":["open-webui@<= 0.8.8 (fixed: 0.8.9)"],"epssScore":0.00392},{"id":"c20a4c42-169b-43a2-bffb-0863a4bfd895","url":"https://aisecwatch.com/issues/c20a4c42-169b-43a2-bffb-0863a4bfd895","cveId":"CVE-2026-45346","title":"GHSA-r29h-37fj-x2w6: Open WebUI Has Stored Cross-Site Scripting in SVG Renderer","headline":null,"severity":"medium","publishedAt":"2026-05-14T20:21:51.000Z","affected":["open-webui@< 0.6.31 (fixed: 0.6.31)"],"epssScore":0.00239},{"id":"2204c870-46a9-414c-91b8-acce913beebf","url":"https://aisecwatch.com/issues/2204c870-46a9-414c-91b8-acce913beebf","cveId":"CVE-2026-44571","title":"GHSA-jgj3-r8hr-9pjw: Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission","headline":null,"severity":"medium","publishedAt":"2026-05-11T14:05:24.000Z","affected":["open-webui@<= 0.8.5 (fixed: 0.8.6)"],"epssScore":0.00336},{"id":"3eb963e5-521f-4e79-ab62-70438cc98ea6","url":"https://aisecwatch.com/issues/3eb963e5-521f-4e79-ab62-70438cc98ea6","cveId":"CVE-2026-44567","title":"GHSA-4vg5-rp28-gvjf: Open WebUI has Improper Authorization Control","headline":null,"severity":"high","publishedAt":"2026-05-08T22:34:12.000Z","affected":["open-webui@<= 0.1.123 (fixed: 0.1.124)"],"epssScore":0.00338},{"id":"a5747021-3908-4347-9d0f-cb612e3f2213","url":"https://aisecwatch.com/issues/a5747021-3908-4347-9d0f-cb612e3f2213","cveId":"CVE-2026-29071","title":"GHSA-w9f8-gxf9-rhvw: Open WebUI's Insecure Direct Object Reference (IDOR) allows access to other users' memories","headline":null,"severity":"low","publishedAt":"2026-03-27T15:35:49.000Z","affected":["open-webui@<= 0.8.5 (fixed: 0.8.6)"],"epssScore":0.00265},{"id":"445f8336-b67b-460d-990e-62304d2f9830","url":"https://aisecwatch.com/issues/445f8336-b67b-460d-990e-62304d2f9830","cveId":"CVE-2026-28788","title":"GHSA-jjp7-g2jw-wh3j: Open WebUI's process_files_batch() endpoint missing ownership check, allows unauthorized file overwrite","headline":null,"severity":"high","publishedAt":"2026-03-27T15:34:26.000Z","affected":["open-webui@< 0.8.6 (fixed: 0.8.6)"],"epssScore":0.0038},{"id":"d188bb48-ffcc-4892-9a1c-c6ddde3a783e","url":"https://aisecwatch.com/issues/d188bb48-ffcc-4892-9a1c-c6ddde3a783e","cveId":"CVE-2026-28786","title":"GHSA-vvxm-vxmr-624h: Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions`","headline":null,"severity":"medium","publishedAt":"2026-03-27T15:29:32.000Z","affected":["open-webui@< 0.8.6 (fixed: 0.8.6)"],"epssScore":0.00421},{"id":"59f6fd4f-de29-4d09-8905-7457e43c7c10","url":"https://aisecwatch.com/issues/59f6fd4f-de29-4d09-8905-7457e43c7c10","cveId":"CVE-2024-6706","title":"CVE-2024-6706: Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the…","headline":"Language model prompt injection enabling cross-site scripting in web page","severity":"medium","publishedAt":"2024-08-07T23:15:41.350Z","affected":["open-webui@<= 0.1.105"],"epssScore":0.00657}],"checkedAt":"2026-10-09T21:59:18.269Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}