Bounties
Partners
Community
Info
open-webui / open-webui
Project repository
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
26 DAYS
FIX
WITHIN
N/A DAYS
Command injection via frontmatter requirements in pip install
May 18th 2026
lewiswigmore
•
self closed
SSRF Filter Bypass via HTTP Redirect in /api/v1/retrieval/process/web (bypasses...
May 8th 2026
zeetop1v
•
duplicate
High
Systemic SSRF via Multiple Bypass Vectors in RAG URL Processing
May 8th 2026
saifullahsayyed
•
duplicate
High
Systemic SSRF Bypasses (TOCTOU, DNS Rebinding, Parse Confusion) in RAG Pipeline...
May 7th 2026
saifullahsayyed
•
self closed
CRITICAL: Multiple SSRF Bypasses in RAG Web Retrieval via Parse Confusion, HTTP...
May 6th 2026
saifullahsayyed
•
self closed
Calendar event update can move events into read-only shared calendars in open-we...
May 2nd 2026
76embiid21
•
self closed
open-webui: SSRF via redirect-following bypass in URL retrieval — validate_url c...
May 8th 2026
mr-white-hat
•
duplicate
High
Authenticated Remote Code Execution via Tool Creation exec() in Open WebUI
Apr 18th 2026
dorkerdevil
•
duplicate
Critical
Missing message ownership check allows any group/DM channel member to edit and d...
Apr 6th 2026
vuvannam-sec
•
self closed
Privilege escalation in channel access control: public read access grants unauth...
Mar 25th 2026
dralexharrison
•
self closed
Unauthenticated access to embedding endpoint allows resource abuse without rate...
Apr 23rd 2026
radikhoroshev
•
self closed
SSRF to Cloud Instance Metadata via HTTP Redirect and Blocklist Bypass
May 8th 2026
seory0
•
duplicate
High
SSRF via DNS rebinding in URL validation bypass (developer-acknowledged)
Mar 15th 2026
eistee82
•
self closed
Un sandboxed exec() on user-supplied Python code in tool creation enables non-ad...
Apr 18th 2026
hkhan0
•
duplicate
Critical
SSRF via DNS rebinding in retrieval endpoints allows access to internal services
May 22nd 2026
egegoker35
•
duplicate
Medium
SSRF via User-Controlled Webhook URL in Channel Notifications
May 21st 2026
optimus-fulcria
•
pending
Authenticated IDOR in /api/v1/chats/{id} allows unauthorized deletion of user co...
May 17th 2026
ayhan8286
•
pending
Cloud Metadata SSRF Blocklist Bypass
May 13th 2026
seory0
•
duplicate
Medium
Full-read SSRF via DNS rebinding in /api/v1/retrieval/process/web — acknowledged...
May 7th 2026
iiviel
•
pending
Remote Code Execution via exec() in plugin.py Tool/Function Loading
May 3rd 2026
222n5
•
pending
Users can invoke code interpreter via api after code execution is disabled
Apr 12th 2026
eliyastein
•
pending
Server-Side Request Forgery (SSRF) in Image URL Processing allows authenticated...
Apr 4th 2026
alearner12
•
pending
Unauthorized access to User Notes
Nov 14th 2025
python4004
•
pending
Leak of sensitive information
May 18th 2026
haoami
•
self closed
XSS vulnerability in model loading of open-webui/open-webui
Sep 16th 2025
zzc-river
•
pending
Stored XSS in Artifact Rendering
Sep 14th 2025
xqrt
•
pending
Administrator permission Remote command execution
Sep 7th 2025
hyperlyz
•
pending
RCE in load_tool_module_by_id Function Due to unsafe code injection
Sep 7th 2025
hyperlyz
•
pending
DoS: Normal User Kicks Out Anyone Including Admin's Use of LLM Answer
Aug 21st 2025
pricx
•
pending
Stored XSS via unescaped markdown token
Jul 26th 2025
choket
•
pending
Unauthorized File Access on api/v1/retrieval/process/file
Jul 22nd 2025
bcur1ous
•
pending
Privilege Escalation through the OpenAI API endpoint on open-webui
Jul 22nd 2025
bcur1ous
•
pending
Full response ssrf in https://github.com/open-webui/open-webui/
Jul 20th 2025
bcur1ous
•
pending
Model file upload involves path traversal(/ollama/models/upload)
Mar 11th 2025
kyo-w
•
duplicate
Critical
Unexpected startup script causing JWT forgery
Jun 3rd 2025
ch1y4n
•
pending
Unauthenticated Denial of Service `api/v1/utils/markdown`
Apr 7th 2026
keanu-k
•
self closed
Unauthenticated Denial of Service (DoS) due to the absence of filename validatio...
May 21st 2025
c2an1
•
pending
User can bypass chat deletion prevention by deleting chat folder instead
Mar 13th 2025
bober182
•
pending
Stored XSS in due get_html_file_content_by_id function lead to Privilage Esclati...
Dec 12th 2024
omidxrz
•
duplicate
High
Data leakage occurs due to CORS misconfiguration
Nov 25th 2024
glmgbj233
•
duplicate
High
Forced downloading of database by Client-Side Path Traversal
Dec 20th 2024
szarny
•
informative
Medium
Improper Access control to edit another user controls
Dec 20th 2024
ralph13
•
informative
Medium
Concurrent Login
Dec 18th 2024
ralph13
•
spam
Denial of service through memory exhaustion
Jan 20th 2025
patrik-ha
•
High
•
$600
High
•
$600
•
CVE-2024-12868
CVE-2024-12868
Code Injection
Dec 18th 2024
quyenheu
•
duplicate
Critical
Denial of service through code-formatting endpoint
Jan 14th 2025
patrik-ha
•
duplicate
High
Denial of Service (DoS) Due to No Character Limit on Email and Password Fields D...
Jan 9th 2025
mnqazi
•
High
•
$600
High
•
$600
•
CVE-2024-12534
CVE-2024-12534
Unauthenticated Denial of Service `api/v1/utils/code/format`
Jan 9th 2025
mnqazi
•
High
•
$600
High
•
$600
•
CVE-2024-12537
CVE-2024-12537
Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability Across...
Dec 11th 2024
mnqazi
•
High
•
$600
High
•
$600
•
CVE-2024-9840
CVE-2024-9840
Privilege escalation in Allow Chat Editing
Sep 18th 2024
hainguyen0207
•
informative
Medium
Privilege escalation in Admin Panel - Chats
Nov 27th 2024
hainguyen0207
•
duplicate
Medium
IDOR in chats
Nov 21st 2024
hainguyen0207
•
informative
High
Stored XSS in model's response allows attacker to steal API token.
Nov 17th 2024
keeper772
•
duplicate
High
Cross User File Access
Nov 11th 2024
jamoski3112
•
duplicate
Medium
Stored XSS In File Uploads
Nov 7th 2024
jamoski3112
•
duplicate
High
Blind SSRF To Internal Port Scan
Aug 21st 2024
minhquan202
•
informative
Medium
Remote code execution caused by pipeline feature in open-webui
Aug 21st 2024
startr4ck
•
self closed
Admin User Can Delete/Update Information of Other Admin Users
Aug 21st 2024
0xanis
•
informative
High
Unauthorized File Access and Deletion
Nov 4th 2024
0xanis
•
duplicate
Critical
open-webui race competion upload
Nov 3rd 2024
muzai
•
duplicate
High
Stored XSS in Functions Funding URL metadata
Aug 21st 2024
rook1337
•
informative
Medium
Unauthorized users can delete files and reset databases in OpenWeb UI, greatly a...
Oct 31st 2024
startr4ck
•
duplicate
High
File upload traversal Causing RCE Delete/replace any file
Oct 29th 2024
startr4ck
•
duplicate
High
Low Privilege is able to Update memory of admin users
Oct 29th 2024
rook1337
•
duplicate
Medium
Stealing Open_API Key through SSRF in open-webui v0.3.10 (latest)
Oct 28th 2024
bugdisclose
•
duplicate
Medium
Administrator permission Remote command execution
Aug 21st 2024
jiang-niao
•
informative
High
RCE: While uploading the GGUF model, leads to Create/Overwrite any system files....
Oct 25th 2024
mnqazi
•
duplicate
High
Broken Access Control
Aug 21st 2024
githubuser843205
•
informative
Medium
No Authentication at `api/v1/utils/pdf` endpoint, can leads to unauthenticated D...
Oct 25th 2024
mnqazi
•
High
•
$600
High
•
$600
•
CVE-2024-8053
CVE-2024-8053
Delete All The Uploaded Files via Missing Authorization
Oct 22nd 2024
0xe2d0
•
duplicate
High
Unrestricted File upload through /transcriptions endpoint
Oct 21st 2024
rook1337
•
duplicate
Medium
CSRF at `api_key` endpoint, leads to reveal the user API key
Oct 20th 2024
mnqazi
•
duplicate
Medium
Unauthorized Modification of User Memory
Oct 19th 2024
dan-xzero
•
duplicate
High
Unauthorized Access and Deletion of User Chats
Oct 19th 2024
dan-xzero
•
duplicate
High
Unauthorized Workspace Access
Oct 8th 2024
dan-xzero
•
not applicable
Path traversal case arbitrary *py file delete in open-webui
Oct 17th 2024
n0el4kls
•
duplicate
High
XSS to Account Takeover
Oct 17th 2024
williwollo
•
duplicate
Critical
SSRF in many endpoints
Jul 23rd 2024
nduy2110
•
informative
Critical
Stored XSS
Oct 15th 2024
nduy2110
•
duplicate
Critical
Base64 Data URI XSS in Profile Picture Functionality
Aug 19th 2024
saimanikanta1992
•
duplicate
High
File upload leads to Stored XSS
Oct 14th 2024
0xe2d0
•
duplicate
High
Unauthen Information disclosure
Aug 20th 2024
nduy2110
•
informative
Medium
(RBAC issue) Any user can delete the files uploaded by the other users, includin...
Oct 14th 2024
mnqazi
•
duplicate
High
CORS misconfiguration leads to data leak
Oct 14th 2024
mnqazi
•
duplicate
High
Data leak through CORS misconfiguration
Oct 13th 2024
dan-xzero
•
duplicate
Medium
Any user can read files uploaded by other users, including the admin
Oct 13th 2024
mnqazi
•
duplicate
High
Stored XSS via file upload, can affect admin
Oct 13th 2024
mnqazi
•
duplicate
Critical
CSRF lead to Reset Vector Storage, DB, Uploads
Oct 13th 2024
meme-dm
•
duplicate
Medium
Server-Side Request Forgery (SSRF) Vulnerability
Jul 23rd 2024
dan-xzero
•
duplicate
Critical
Server-Side Template Injection (SSTI) in Chat Description Field
Oct 8th 2024
dan-xzero
•
not applicable
Server Side Request Forgery (SSRF) in open-webui / open-webui
Oct 8th 2024
virusday
•
not applicable
Stored XSS via file upload
Oct 12th 2024
web-hacker-team
•
duplicate
Critical
Remote Code Execution
Aug 19th 2024
mvlttt
•
informative
Critical
Arbitrary file write to RCE
Oct 12th 2024
mvlttt
•
duplicate
High
Server-Side Request Forgery SSRF
Aug 21st 2024
mvlttt
•
informative
Critical
Arbitrary file delete
Oct 12th 2024
mvlttt
•
duplicate
High
XSS via chat information tooltip
Oct 12th 2024
lambdasawa
•
Critical
•
$1200
Critical
•
$1200
•
CVE-2024-8017
CVE-2024-8017
Stored Cross Site Scripting in model description Due to Sanitization Bypass
Oct 12th 2024
m0kr4n3
•
High
•
$600
High
•
$600
•
CVE-2024-7990
CVE-2024-7990
Unrestricted File Upload Leading to XSS and Other Attacks in Chat
Oct 11th 2024
dan-xzero
•
duplicate
Critical
Unauthorized Access to Uploaded Files by Any User
Oct 11th 2024
dan-xzero
•
duplicate
Medium
Cross-Site Scripting (XSS) via Unsanitized Profile Image URL in Registration
Aug 15th 2024
dan-xzero
•
informative
Critical
SSRF Vulnerability Allowing Internal Service Enumeration
Jul 23rd 2024
saimanikanta1992
•
duplicate
High
Denial of Service in multipart/form-data while uploading a file in chat
Oct 11th 2024
srivallikusumba
•
High
•
$600
High
•
$600
•
CVE-2024-7999
CVE-2024-7999
CSRF to Delete Uploaded Rag Files
Oct 11th 2024
zpbrent
•
duplicate
High
Delete arbitrary files via file upload (/ollama/models/upload)
Oct 11th 2024
pyozzi-toss
•
duplicate
Medium
RCE by Non-Admin Users via CSRF
Oct 11th 2024
lambdasawa
•
High
•
$600
High
•
$600
•
CVE-2024-7806
CVE-2024-7806
Directory Removal Without Confirmation
Aug 20th 2024
syed-ghufran-hassan
•
spam
Zero-Click Unauthenticated ( < 0.3.6 ) RCE via path traversal
Oct 11th 2024
patchyst
•
duplicate
Critical
SSRF in /openai/models
Oct 11th 2024
ouxs-19
•
High
•
$600
High
•
$600
•
CVE-2024-7959
CVE-2024-7959
Stored XSS via file upload
Oct 10th 2024
lambdasawa
•
duplicate
Critical
CSRF on endpoints due to overly permissive CORS headers
Oct 10th 2024
patrik-ha
•
duplicate
High
Administrator Account Takeover via Lax Session Cookie
Oct 10th 2024
mblunt
•
High
•
$600
High
•
$600
•
CVE-2024-7053
CVE-2024-7053
Users can view the content of uploaded files in other people's chats
Oct 10th 2024
hainguyen0207
•
duplicate
Medium
SSRF Controlled Race Condition leading to RCE in Pipeline Upload API
Aug 19th 2024
mblunt
•
informative
Medium
Stored XSS in file upload
Oct 10th 2024
ouxs-19
•
duplicate
Critical
Denial of service through endpoint for converting markdown
Oct 10th 2024
patrik-ha
•
High
•
$600
High
•
$600
•
CVE-2024-7983
CVE-2024-7983
Arbitrary file overwrite by model upload
Oct 10th 2024
patrik-ha
•
duplicate
High
Low Privilege user can upload documents in Workspace document upload feature
Oct 10th 2024
rook1337
•
duplicate
Medium
Store Open Redirect at Profile Image
Jul 23rd 2024
hainguyen0207
•
informative
Medium
CSRF leads to reset memories
Oct 10th 2024
ngductung
•
duplicate
Medium
DDOS and SSRF at Images URL Update endpoint
Jul 23rd 2024
rook1337
•
duplicate
Medium
No Rate limiting on Login page leads to credentials bruteforce
Jul 23rd 2024
rook1337
•
informative
Medium
IDOR view+delete all file in aplication
Oct 10th 2024
duongli99
•
duplicate
High
Improper access control-allow view any prompts
Oct 10th 2024
fewword
•
Medium
•
$100
Medium
•
$100
•
CVE-2024-7045
CVE-2024-7045
Improper access control-allow view any tools info
Aug 20th 2024
fewword
•
informative
High
Token returned when the user account logs in - with Role as Pending. Waiting for...
Oct 10th 2024
hainguyen0207
•
Medium
•
$100
Medium
•
$100
•
CVE-2024-7049
CVE-2024-7049
Security issue in session
Aug 14th 2024
hainguyen0207
•
informative
High
Improper access control-allow view any functions info
Aug 20th 2024
fewword
•
informative
Medium
•
CVE-2024-7051
CVE-2024-7051
Improper access control-allow view/delete any files
Oct 10th 2024
fewword
•
High
•
$600
High
•
$600
•
CVE-2024-7043
CVE-2024-7043
Stored XSS via upload file in chat
Oct 10th 2024
ngductung
•
Medium
•
$100
Medium
•
$100
•
CVE-2024-7044
CVE-2024-7044
Arbitrary file writing lead to Remote Code Execution
Oct 10th 2024
j0ok34n
•
duplicate
Critical
Improper access control-allow view admin details
Oct 10th 2024
fewword
•
Medium
•
$100
Medium
•
$100
•
CVE-2024-7046
CVE-2024-7046
IDOR- allow to update any memory
Oct 10th 2024
fewword
•
duplicate
High
Limited SSRF via Speech-to-Text Engine Configuration
Jul 23rd 2024
mblunt
•
informative
Medium
Privilege Escalation Vulnerability to update default model
Jul 23rd 2024
fewword
•
informative
Medium
Arbitrary File Delete
Oct 10th 2024
vn-ncvinh
•
duplicate
Critical
RCE in OpenWebUI v0.3.0 via Arbitrary File Upload
Oct 10th 2024
mblunt
•
High
•
$600
High
•
$600
•
CVE-2024-8060
CVE-2024-8060
Use weak passwords
Jul 23rd 2024
duongli99
•
informative
Medium
CSRF_reset db
Oct 10th 2024
duongli99
•
duplicate
Medium
CSRF in /rag/api/v1/reset
Oct 10th 2024
j0ok34n
•
duplicate
High
CSRF in /rag/api/v1/reset/uploads
Oct 10th 2024
vn-ncvinh
•
duplicate
High
Path traversal leads to create and overwrite any file
Oct 10th 2024
fewword
•
duplicate
High
Arbitrary .py File Deletion via Path Traversal
Oct 10th 2024
vn-ncvinh
•
duplicate
High
Remote Code Execution through Model Upload
Oct 10th 2024
lismaps
•
duplicate
High
Show more...
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0