CVE-2026-0765
| CVE ID | CVE-2026-0765 |
| Vendor Disposition | Rejected, not a vulnerability |
| Published | 2026-01-23 |
| Issuing CNA | Zero Day Initiative (ZDI-26-031) |
| Claimed Severity | High (CVSS 8.8, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
Timeline
This CVE is formally disputed. The dispute is open and being pursued through the CVE Program's process; the assessment below is Open WebUI's position in the meantime.
| Date | Event |
|---|---|
| 2025-10 | ZDI submits the underlying report through Open WebUI's security channel. Open WebUI closes it as out of scope and not a vulnerability under its published security policy, but does so without giving the reporter a written explanation at the time, which was a mistake on Open WebUI's part. |
| 2026-01-23 | ZDI publishes the CVE (ZDI-26-031). |
| 2026-05-04 | Open WebUI files a formal dispute with the CVE Program and notifies ZDI directly. Neither ZDI nor the CVE Program responds. |
| 2026-06-15 | Open WebUI files another dispute with the CVE Program; the Secretariat directs it to the issuing CNA (ZDI), which owns the record. The request is subsequently closed. |
| 2026-07-02 | With the CNA non-responsive, Open WebUI escalates the dispute a third time, to the CVE Program's Root / Top-Level Root under the CVE Record Dispute Policy (v2.0.0). |
| 2026-07-06 | Under the CVE Program's record-dispute procedure, the Program forwards the dispute to the issuing CNA (ZDI) for its determination. |
As of 2026-07-06, the dispute is before the issuing CNA (ZDI) for its determination and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
What the CVE Claims
The function install_frontmatter_requirements in backend/open_webui/utils/plugin.py allegedly allows a low-privileged authenticated remote attacker to execute arbitrary code by injecting malicious package names into the requirements field of a Tool's or Function's YAML frontmatter, which the function then passes to pip install via subprocess.check_call.
Why This Is Not a Vulnerability
install_frontmatter_requirements is the documented mechanism by which Open WebUI installs Python package dependencies declared in the YAML frontmatter of user-authored Tools and Functions. Tools and Functions are user-authored Python modules that the server loads, executes, and holds in memory. Authors declare pip dependencies via frontmatter, and the server resolves them on first load. This mirrors the dependency-declaration model of comparable extension systems (Jupyter notebooks with %pip install, n8n Code nodes, Home Assistant python_script).
There is no "injection" into a fixed pipeline. The user is not injecting commands into someone else's operation. They are submitting Python source code that includes a declared dependency list, and the server installs those dependencies and executes the code by design. The "attacker" in this scenario is a user exercising the code-execution rights they were explicitly granted.
Access Control
The function is reachable only through admin-gated routes (POST /api/v1/tools/create, POST /api/v1/tools/id/{id}/update, and analogous Function endpoints). These routes require either user.role == 'admin' or the workspace.tools permission, which is disabled by default for non-admin users. Granting workspace.tools is documented as equivalent to giving the user shell access to the server. There is no path by which an unprivileged user can reach this function.
Severity
Because this is intended behavior and not a vulnerability, no CVSS score applies to it; the published 8.8 (High) scores a capability the software is designed to provide. Separately, and only if the record is scored at all, the vector's PR:L (privileges required, low) is inaccurate: the function is reachable only by an administrator, or by a user an administrator has granted the root-equivalent workspace.tools permission, which is PR:H. This is recorded for completeness and does not bear on the disposition, which is out of scope on the intended-behavior basis regardless of severity.
Applicable Security Policy Rules
- Rule 10: Reports involving Tools or Functions, including code execution and frontmatter-based pip installation, are closed as intended behavior.
- Rule 9: "Pasting untrusted code into Functions/Tools" is explicitly cited as out-of-scope.
- Rule 1: Expected protocol behavior is not a vulnerability.
Impact to Users
No action required. This CVE describes intended functionality. If you have granted workspace.tools to untrusted users, review the Plugin Security documentation, but this is a configuration decision, not a vulnerability.