BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Open WebUI's 0.11.4 security fixes were still missing from GitHub and OSV advisory records on 11 October
At least 15 Open WebUI advisories fixed in 0.11.4, one a CVSS 8.1 session-token theft, were missing from GitHub's advisory database and OSV on 11 October. Scanners reading those databases can report 0.11.1 to 0.11.3 as clean, a dev.to post found, so operators have to check the version themselves.
The Engineer · Build desk

What happened
- That bug only works with community sharing enabled, and the ENABLE_COMMUNITY_SHARING setting ships switched on.
- The batch also fixes a CVSS 7.6 Terminals bug that let a user with access list and stop other users' terminals and change terminal policies.
- Open WebUI shipped 0.12.0 on 10 October, and its release notes say it includes further security and access-control fixes.
Why it matters
- exposure A stolen token carries the victim's full role through the API, so an admin who browses other sites while signed in exposes everything an admin account can do.
- constraint Upgrade policies driven by scanner findings will not schedule the 0.11.4 upgrade for 0.11.1 to 0.11.3 installs until the database records arrive.
- decision Teams that cannot upgrade today have to switch community sharing off to close the CVSS 8.1 bug, and the link-based token thefts stay open until they do upgrade.
- cost Upgrading does not kill tokens already stolen, so admins also have to force sign-outs, through the every-device control added in 0.12.0 or a password change.
The CVSS 8.1 bug comes down to one unchecked origin. A dev.to post summarises the advisory this way: a user signed in to Open WebUI visits an attacker's page in the same browser. That page opens Open WebUI in a popup and receives the user's session token, because a message listener accepted messages from any origin [3]. The attacker needs no account on the server and no action by an admin [6].
Where the server sits on the network makes no difference. The same post advises publishing the container with `-p 127.0.0.1:3000:8080`, or putting it behind a VPN or an authenticating proxy [17]. This attack runs through the victim's own browser, so an instance reachable only on a LAN or over a VPN is still in scope [7].
Scanners miss the batch because the database records stop too early. None of the September advisories has a CVE ID [8]. On 11 October the GitHub Advisory Database API listed Open WebUI advisories only up to the 0.11.1 batch of 10 September, and OSV returned "not found" for GHSA-vpq8-f445-hcq7 [9]. That 0.11.1 batch does have CVE IDs. One is CVE-2026-87016, a High-rated bug that let someone sign in as another account through wildcard characters in OAuth and SCIM lookups on SQLite [13]. A tool that matches an installed version against those feeds finds nothing after 0.11.1 to flag. By the time of that check the September advisories had been public for at least 13 days [21]. The finding covers tools that read those two databases. The post does not test any named scanner, and the records may have been added since its 11 October check [18].
Settings > About shows the installed version [20]. Anything below 0.11.4 needs the upgrade, since every advisory in the batch is fixed there [1]. The same release closes two other routes to a viewer's token: `javascript:` links in chat messages, which affects every version before 0.11.4, and a shared chat's citations, rated High [11].
All of this rests on one post. Its author is MV2 of Munim, Inc., which describes itself as an AI. The post says it checked Open WebUI's advisories and release notes, the GitHub Advisory Database and OSV on 11 October [18]. The same author maintains local-ai-checkup, a free, MIT-licensed, read-only Python script that checks Open WebUI versions against these advisories, including the ones without CVE IDs [19]. In our view a manual comparison against 0.11.4 gives the same answer for this batch [1].
What to watch
- Whether the GitHub Advisory Database and OSV ingest the 27 and 28 September advisories, and whether any of them is assigned a CVE ID.
- Whether the security and access-control fixes cited in the 0.12.0 release notes get advisories of their own, and how long those take to reach the same databases.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence42
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On 27 and 28 September 2026, Open WebUI published a batch of at least 15 security advisories, every one of which is fixed in 0.11.4.
- [2]
GHSA-vpq8-f445-hcq7 is rated High, CVSS 8.1, and affects Open WebUI 0.7.0 up to 0.11.4.
- [3]
A user signed in to Open WebUI who visits an attacker's web page in the same browser can have that page open Open WebUI in a popup and receive the session token; a message listener accepted messages from any origin.
- [4]
The stolen token gives full API access as the user, covering private chats and anything the user's role can do.
- [5]
The precondition for GHSA-vpq8-f445-hcq7 is that community sharing (ENABLE_COMMUNITY_SHARING) is on, and it is on by default.
- [6]
The attacker does not need an account on the server or any admin action.
- [7]
Because the attack runs through the user's own browser, an Open WebUI instance reachable only on a LAN or over a VPN is still in scope.
- [8]
None of the September 2026 Open WebUI advisories has a CVE ID.
- [9]
As of 11 October 2026, the GitHub Advisory Database API lists Open WebUI advisories only up to the 0.11.1 batch from 10 September, and OSV returns "not found" for GHSA-vpq8-f445-hcq7.
- [10]
Dependency scanners that read the GitHub Advisory Database or OSV can report Open WebUI 0.11.1, 0.11.2 or 0.11.3 as clean.
- [11]
0.11.4 fixes viewer token theft through javascript: links in chat messages (GHSA-wf9m-46cp-c6h6, every version before 0.11.4) and through a shared chat's citations (GHSA-qpqv-xwg8-cqpj, High).
- [12]
On servers with a Terminals connection, a user with access could list and stop other users' terminals and change terminal policies (GHSA-q46m-r89w-j74p, High, CVSS 7.6); fixed in 0.11.4.
- [13]
Two weeks earlier, 0.11.1 fixed a batch that has CVE IDs, including signing in as another account through wildcard characters in OAuth/SCIM lookups on SQLite (CVE-2026-87016, High).
- [14]
The current release is 0.12.0, dated 10 October 2026; its notes say it "includes security and access-control fixes".
- [15]
The advisory says deployments with community sharing off (ENABLE_COMMUNITY_SHARING=False) are not affected by GHSA-vpq8; the link-based bugs still need the update.
- [16]
A token stolen before the update may still work until it expires; 0.12.0 adds a way for admins to sign a user out of every device, and changing a password now does the same.
- [17]
The post advises publishing Open WebUI as -p 127.0.0.1:3000:8080, or behind a VPN or an authenticating proxy, with login kept on.
- [18]
The post was written by MV2 of Munim, Inc., which identifies itself as an AI, and says its facts come from Open WebUI's security advisories and release notes, the GitHub Advisory Database and OSV, all checked on 11 October 2026.
- [19]
The author maintains local-ai-checkup, a free, MIT-licensed, read-only Python script that checks Open WebUI, Ollama and ComfyUI versions against these advisories, including the ones without CVE IDs.
- [20]
The Open WebUI version is shown under Settings > About.
- [21]
The September advisories had been published for at least 13 days when they were found missing from the databases on 11 October 2026.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.