Vendor Dispositions
Open WebUI's formal assessments of externally reported CVEs and security claims.
When a CVE is filed against Open WebUI, we evaluate the report against our Security Policy, our documented threat model, and the actual behavior of the software. If a report is inaccurate, mischaracterized, or does not represent a genuine vulnerability, we publish a vendor disposition here explaining our assessment.
For our position on automated supply-chain scanner indicators (socket.dev and similar) rather than specific CVEs, see Supply Chain and Security Scanners.
What Is a Vendor Disposition?
A vendor disposition is the software vendor's official, public response to a CVE or vulnerability report. It is a standard part of the coordinated vulnerability disclosure process and serves several purposes:
- Transparency: Users and administrators can see exactly how we evaluated a claim and why we reached our conclusion.
- Accuracy: CVE databases sometimes contain reports that misrepresent severity, misunderstand the threat model, or describe intended behavior as a vulnerability. Dispositions correct the public record.
- Guidance: Each disposition includes context that helps administrators assess whether the reported issue is relevant to their specific deployment.
Threat Model
Open WebUI is a self-hosted, single-tenant, authenticated, role-based application. It can be deployed publicly, but requires proper configuration (TLS termination, reverse proxy, appropriate access controls). Our threat model assumes:
- All users are authenticated before accessing any functionality.
- Administrators are trusted actors with full system control.
- Security settings are at their defaults or tighter: the threat model does not assume intentional weakening of security settings. Valid vulnerability reports must be reproducible on default or stricter configurations.
- Tools, Functions, and Pipelines execute arbitrary code by design: this is a feature, not a vulnerability. Administrators control who can install and use them.
Reports that ignore these architectural assumptions, for example, claiming a vulnerability that requires admin-level access, intentionally weakened settings, or misconfigured deployments, may be disputed.
For a full overview, see the Security Policy.
All Dispositions
| CVE | Title | Issuing CNA | Vendor Disposition | Resolution | CVE Published |
|---|---|---|---|---|---|
| CVE-2026-0765 | PIP install_frontmatter_requirements Command Injection | Zero Day Initiative | Rejected | In progress | 2026-01-23 |
| CVE-2026-0766 | load_tool_module_by_id Code Injection | Zero Day Initiative | Rejected | In progress | 2026-01-23 |
| CVE-2026-0767 | Cleartext Transmission of Credentials | Zero Day Initiative | Rejected | In progress | 2026-01-23 |
| CVE-2025-15603 | Insufficiently Random Values in start_windows.bat | VulDB | Rejected | CNA REJECTED | 2026-03-09 |
| CVE-2025-29446 | SSRF in verify_connection | MITRE | Rejected | CNA REJECTED | 2025-04-21 |
| CVE-2025-63391 | Authentication Bypass in /api/config | MITRE (CISA-ADP enrichment) | Rejected | CNA REJECTED | 2025-12-18 |
| CVE-2024-7033 | Path Traversal in Model Download | huntr / Protect AI | Rejected | CNA REJECTED | 2025-03-20 |
| CVE-2024-7034 | Path Traversal in Model Upload | huntr / Protect AI | Rejected | CNA REJECTED | 2025-03-20 |
| CVE-2024-7036 | DoS via Oversized Signup Name | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-7037 | Path Traversal in Pipeline Upload | huntr / Protect AI | Rejected | In progress | 2024-10-09 |
| CVE-2024-7038 | Path Oracle in Embedding-Model Update | huntr / Protect AI | Rejected | CNA REJECTED | 2024-10-09 |
| CVE-2024-7039 | Cross-Admin User Deletion | huntr / Protect AI | Rejected | CNA REJECTED | 2025-03-20 |
| CVE-2024-7040 | Cross-Admin Chat Access via user_id Parameter | huntr / Protect AI | Rejected | CNA REJECTED | 2025-10-15 |
| CVE-2024-7045 | Prompt Disclosure via /api/v1/prompts/ | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-7046 | Admin Details Disclosure via /api/v1/auths/admin/details | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-7053 | Session Fixation via Markdown Image | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-7959 | SSRF via Admin-Configured OpenAI URL | huntr / Protect AI | Rejected | CNA REJECTED | 2025-03-20 |
| CVE-2024-7990 | Stored XSS via Model Description | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-8060 | Path Traversal in Audio Transcription Upload | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-12534 | DoS via Oversized Sign-in Fields | huntr / Protect AI | Rejected | In progress | 2025-03-20 |
| CVE-2024-12537 | DoS via Code Format Endpoint | huntr / Protect AI | Rejected | In progress | 2025-03-20 |