Published issues
Permalink
CVE-2026-45349
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: Broken Access Control for Completions API
Permalink
CVE-2026-45401
8.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints
Permalink
CVE-2026-45385
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: An IDOR vulnerability exists in the update_message_by_id API endpoint
Permalink
CVE-2026-45772
0.0 NONE
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
ignored
31 packages
- aws-workspaces
- cargo-workspaces
- hyprland-workspaces
- turborepo-remote-cache
- cosmic-workspaces-epoch
- hyprland-workspaces-tui
- xfce4-i3-workspaces-plugin
- hyprland-autoname-workspaces
- kdePackages.dynamic-workspaces
- xfce.xfce4-i3-workspaces-plugin
- gnomeExtensions.named-workspaces
- gnomeExtensions.reorder-workspaces
- gnomeExtensions.vertical-workspaces
- haskellPackages.amazonka-workspaces
- gnomeExtensions.workspaces-organizer
- gnomeExtensions.simple-workspaces-bar
- gnomeExtensions.vscode-workspaces-gnome
- haskellPackages.amazonka-workspaces-web
- python312Packages.mypy-boto3-workspaces
- python313Packages.mypy-boto3-workspaces
- python314Packages.mypy-boto3-workspaces
- vscode-extensions.iciclesoft.workspacesort
- python312Packages.mypy-boto3-workspaces-web
- python313Packages.mypy-boto3-workspaces-web
- python314Packages.mypy-boto3-workspaces-web
- python312Packages.types-aiobotocore-workspaces
- python313Packages.types-aiobotocore-workspaces
- gnomeExtensions.workspaces-indicator-by-open-apps
- python312Packages.types-aiobotocore-workspaces-web
- python313Packages.types-aiobotocore-workspaces-web
- gnomeExtensions.switch-workspaces-on-active-monitor
4 weeks, 1 day ago
-
@LeSuisse
restored
package aws-workspaces
4 weeks, 1 day ago
-
@LeSuisse
added
2 maintainers
4 weeks, 1 day ago
maintainer.add
-
@LeSuisse
ignored
2 maintainers
4 weeks, 1 day ago
maintainer.ignore
-
@LeSuisse
ignored
package aws-workspaces
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Turborepo: Unexpected local code execution during Yarn Berry detection
codemod
turborepo
workspaces
Permalink
CVE-2026-44554
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Permalink
CVE-2026-44721
7.3 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: Stored XSS via Model Description
Permalink
CVE-2026-44560
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Permalink
CVE-2026-45339
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
Permalink
CVE-2026-44558
5.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: Channel Access Grants Bypass filter_allowed_access_grants
Permalink
CVE-2026-44551
9.1 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
4 weeks, 1 day ago
by @LeSuisse
Activity log
-
Created suggestion
4 weeks, 1 day ago
-
@LeSuisse
accepted
4 weeks, 1 day ago
-
@LeSuisse
published on GitHub
4 weeks, 1 day ago
Open WebUI: LDAP Empty Password Authentication Bypass