By vendor

Openwebui vulnerabilities

Known CVEs affecting Openwebui products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-54017HIGH 7.7

    Open WebUI, a self-hosted AI platform, contains a path traversal vulnerability in its terminal-server reverse proxy. An authenticated user with terminal access can manipulate the request path using encoded traversal sequences (like `../`) to bypass intended boundaries and reach files or endpoints they shouldn't access on the terminal server or connected internal services. The vulnerability affects versions before 0.9.6 and requires valid user authentication to exploit, but no special privileges beyond terminal access.