BlackTreeCVE IntelligenceOfficial source evidencegithub.comVersioned article
Official source article · github.com
Release v0.11.1 · open-webui/open-webui · GitHub
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs17
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
- CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
- CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
- CVE-2026-87011Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
- CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
- CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
- CVE-2026-87012Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
- CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
- CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
- CVE-2026-87013Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
- CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
- CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
- CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
- CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
Source and provenance
Original title: Release v0.11.1 · open-webui/open-webui · GitHub. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗