Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
Permalink CVE-2025-15603
3.7 LOW
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
updated 1 week, 4 days ago by @mweinelt Activity log
  • Created automatic suggestion
  • @mweinelt dismissed
open-webui JWT Key start_windows.bat random values

A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

Affected products

open-webui
  • ==0.6.1
  • ==0.6.15
  • ==0.6.5
  • ==0.6.10
  • ==0.6.0
  • ==0.6.2
  • ==0.6.6
  • ==0.6.16
  • ==0.6.4
  • ==0.6.7
  • ==0.6.14
  • ==0.6.11
  • ==0.6.13
  • ==0.6.3
  • ==0.6.9
  • ==0.6.8
  • ==0.6.12

Matching in nixpkgs

Package maintainers

0.6.x is older than everything we have