Skip to main content

Vendor Dispositions

Open WebUI's formal assessments of externally reported CVEs and security claims.

When a CVE is filed against Open WebUI, we evaluate the report against our Security Policy, our documented threat model, and the actual behavior of the software. If a report is inaccurate, mischaracterized, or does not represent a genuine vulnerability, we publish a vendor disposition here explaining our assessment.

Automated scanner flags

For our position on automated supply-chain scanner indicators (socket.dev and similar) rather than specific CVEs, see Supply Chain and Security Scanners.


What Is a Vendor Disposition?

A vendor disposition is the software vendor's official, public response to a CVE or vulnerability report. It is a standard part of the coordinated vulnerability disclosure process and serves several purposes:

  • Transparency: Users and administrators can see exactly how we evaluated a claim and why we reached our conclusion.
  • Accuracy: CVE databases sometimes contain reports that misrepresent severity, misunderstand the threat model, or describe intended behavior as a vulnerability. Dispositions correct the public record.
  • Guidance: Each disposition includes context that helps administrators assess whether the reported issue is relevant to their specific deployment.

Threat Model

Open WebUI is a self-hosted, single-tenant, authenticated, role-based application. It can be deployed publicly, but requires proper configuration (TLS termination, reverse proxy, appropriate access controls). Our threat model assumes:

  • All users are authenticated before accessing any functionality.
  • Administrators are trusted actors with full system control.
  • Security settings are at their defaults or tighter: the threat model does not assume intentional weakening of security settings. Valid vulnerability reports must be reproducible on default or stricter configurations.
  • Tools, Functions, and Pipelines execute arbitrary code by design: this is a feature, not a vulnerability. Administrators control who can install and use them.

Reports that ignore these architectural assumptions, for example, claiming a vulnerability that requires admin-level access, intentionally weakened settings, or misconfigured deployments, may be disputed.

For a full overview, see the Security Policy.

All Dispositions

CVETitleIssuing CNAVendor DispositionResolutionCVE Published
CVE-2026-0765PIP install_frontmatter_requirements Command InjectionZero Day InitiativeRejectedIn progress2026-01-23
CVE-2026-0766load_tool_module_by_id Code InjectionZero Day InitiativeRejectedIn progress2026-01-23
CVE-2026-0767Cleartext Transmission of CredentialsZero Day InitiativeRejectedIn progress2026-01-23
CVE-2025-15603Insufficiently Random Values in start_windows.batVulDBRejectedCNA REJECTED2026-03-09
CVE-2025-29446SSRF in verify_connectionMITRERejectedCNA REJECTED2025-04-21
CVE-2025-63391Authentication Bypass in /api/configMITRE (CISA-ADP enrichment)RejectedCNA REJECTED2025-12-18
CVE-2024-7033Path Traversal in Model Downloadhuntr / Protect AIRejectedCNA REJECTED2025-03-20
CVE-2024-7034Path Traversal in Model Uploadhuntr / Protect AIRejectedCNA REJECTED2025-03-20
CVE-2024-7036DoS via Oversized Signup Namehuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-7037Path Traversal in Pipeline Uploadhuntr / Protect AIRejectedIn progress2024-10-09
CVE-2024-7038Path Oracle in Embedding-Model Updatehuntr / Protect AIRejectedCNA REJECTED2024-10-09
CVE-2024-7039Cross-Admin User Deletionhuntr / Protect AIRejectedCNA REJECTED2025-03-20
CVE-2024-7040Cross-Admin Chat Access via user_id Parameterhuntr / Protect AIRejectedCNA REJECTED2025-10-15
CVE-2024-7045Prompt Disclosure via /api/v1/prompts/huntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-7046Admin Details Disclosure via /api/v1/auths/admin/detailshuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-7053Session Fixation via Markdown Imagehuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-7959SSRF via Admin-Configured OpenAI URLhuntr / Protect AIRejectedCNA REJECTED2025-03-20
CVE-2024-7990Stored XSS via Model Descriptionhuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-8060Path Traversal in Audio Transcription Uploadhuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-12534DoS via Oversized Sign-in Fieldshuntr / Protect AIRejectedIn progress2025-03-20
CVE-2024-12537DoS via Code Format Endpointhuntr / Protect AIRejectedIn progress2025-03-20
This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.