CVE-2026-44552: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When...
Added to the CISA Known Exploited Vulnerabilities catalog on 15 May 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 8.7.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the tool_servers and terminal_servers keys in utils/tools.py do use a prefix. When two or more Open WebUI instances share a Redis database (a supported and documented deployment patt...
Required action: Review and patch if applicable to your AI infrastructure.