Axxemble
| Product | Axxemble vulnerability database |
| Records still shown as active | 1 |
| First contacted | 2026-08-08 |
| Channels tried | [email protected] |
| Status | Awaiting response |
Records
CVE-2025-15603
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| What Axxemble displays | An active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, with no rejection marker, accompanied by an "AI Analysis" stating the issue is remotely exploitable |
| Our assessment | CVE-2025-15603 |
The generated analysis is wrong on the substance, independently of the withdrawal. The behaviour the report described was never remotely exploitable. It concerned a default value in a Windows batch file, and the issuing CNA withdrew the identifier on exactly that basis. Its published rejection reads:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor explains: "The 't0p-s3cr3t' default was dead code on every supported startup path: start.sh, start_windows.bat and
open-webui serveall set or auto-generate WEBUI_SECRET_KEY before the backend imports env.py. It was only ever reachable by invoking uvicorn directly, which is unsupported and unsafe (the app would then sign tokens/cookies with a public, hardcoded key)."
Dead code on every supported startup path, reachable only by someone already running the process by hand on the machine, is not a remotely exploitable condition. The generated paragraph asserts something the report never claimed and the CNA expressly rejected.
A machine-generated paragraph asserting remote exploitability, attached to a withdrawn record, states something stronger than the original report ever claimed and stronger than the CNA ever accepted.
Contact log
| Date | Channel | Outcome |
|---|---|---|
| 2026-08-08 | [email protected] | Awaiting response |
See also
- Rejected CVEs in Vulnerability Databases — the overview and how to verify any record yourself.
- CVE-2025-15603 vendor disposition