FAIL › dossier
openwebui
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-07-09 | CVE-2026-59216 | high | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authentica |
| 2026-07-09 | CVE-2026-59214 | high | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpReques |
| 2026-07-15 | CVE-2026-56398 | high | CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in |
| 2026-07-15 | CVE-2026-56400 | high | CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati |