Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Open WebUI has unauthorized deletion of knowledge files
Open WebUI has an LDAP Empty Password Authentication Bypass
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Open WebUI Allows Arbitrary File Write via the `download_model` Endpoint
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Open WebUI Vulnerable to a Session Fixation Attack
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Other AI / ML projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Open WebUI — without relying on volunteer maintainers.
Talk to an Expert →