Skip to content
COOEY

FAIL › dossier

openwebui

VENDOR

Dossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2026-07-09 CVE-2026-59216 high Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authentica
2026-07-09 CVE-2026-59214 high Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpReques
2026-07-15 CVE-2026-56398 high CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
2026-07-15 CVE-2026-56400 high CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati