CVE-2026-44550: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary ...
Added to the CISA Known Exploited Vulnerabilities catalog on 15 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 5.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fields to pass through Pydantic validation and be included in model_dump(exclude_unset=True). In ins...
Required action: Review and patch if applicable to your AI infrastructure.