Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Open WebUI's 0.11.4 security fixes were still missing from GitHub and OSV advisory records on 11 October

At least 15 Open WebUI advisories fixed in 0.11.4, one a CVSS 8.1 session-token theft, were missing from GitHub's advisory database and OSV on 11 October. Scanners reading those databases can report 0.11.1 to 0.11.3 as clean, a dev.to post found, so operators have to check the version themselves.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Open WebUI's 0.11.4 security fixes were still missing from GitHub and OSV advisory records on 11 October
Generated illustration

What happened

  • That bug only works with community sharing enabled, and the ENABLE_COMMUNITY_SHARING setting ships switched on.
  • The batch also fixes a CVSS 7.6 Terminals bug that let a user with access list and stop other users' terminals and change terminal policies.
  • Open WebUI shipped 0.12.0 on 10 October, and its release notes say it includes further security and access-control fixes.

Why it matters

  • exposure A stolen token carries the victim's full role through the API, so an admin who browses other sites while signed in exposes everything an admin account can do.
  • constraint Upgrade policies driven by scanner findings will not schedule the 0.11.4 upgrade for 0.11.1 to 0.11.3 installs until the database records arrive.
  • decision Teams that cannot upgrade today have to switch community sharing off to close the CVSS 8.1 bug, and the link-based token thefts stay open until they do upgrade.
  • cost Upgrading does not kill tokens already stolen, so admins also have to force sign-outs, through the every-device control added in 0.12.0 or a password change.

The CVSS 8.1 bug comes down to one unchecked origin. A dev.to post summarises the advisory this way: a user signed in to Open WebUI visits an attacker's page in the same browser. That page opens Open WebUI in a popup and receives the user's session token, because a message listener accepted messages from any origin [3]. The attacker needs no account on the server and no action by an admin [6].

Where the server sits on the network makes no difference. The same post advises publishing the container with `-p 127.0.0.1:3000:8080`, or putting it behind a VPN or an authenticating proxy [17]. This attack runs through the victim's own browser, so an instance reachable only on a LAN or over a VPN is still in scope [7].

Scanners miss the batch because the database records stop too early. None of the September advisories has a CVE ID [8]. On 11 October the GitHub Advisory Database API listed Open WebUI advisories only up to the 0.11.1 batch of 10 September, and OSV returned "not found" for GHSA-vpq8-f445-hcq7 [9]. That 0.11.1 batch does have CVE IDs. One is CVE-2026-87016, a High-rated bug that let someone sign in as another account through wildcard characters in OAuth and SCIM lookups on SQLite [13]. A tool that matches an installed version against those feeds finds nothing after 0.11.1 to flag. By the time of that check the September advisories had been public for at least 13 days [21]. The finding covers tools that read those two databases. The post does not test any named scanner, and the records may have been added since its 11 October check [18].

Settings > About shows the installed version [20]. Anything below 0.11.4 needs the upgrade, since every advisory in the batch is fixed there [1]. The same release closes two other routes to a viewer's token: `javascript:` links in chat messages, which affects every version before 0.11.4, and a shared chat's citations, rated High [11].

All of this rests on one post. Its author is MV2 of Munim, Inc., which describes itself as an AI. The post says it checked Open WebUI's advisories and release notes, the GitHub Advisory Database and OSV on 11 October [18]. The same author maintains local-ai-checkup, a free, MIT-licensed, read-only Python script that checks Open WebUI versions against these advisories, including the ones without CVE IDs [19]. In our view a manual comparison against 0.11.4 gives the same answer for this batch [1].

What to watch

  • Whether the GitHub Advisory Database and OSV ingest the 27 and 28 September advisories, and whether any of them is assigned a CVE ID.
  • Whether the security and access-control fixes cited in the 0.12.0 release notes get advisories of their own, and how long those take to reach the same databases.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence48
Adoption
Insufficient
Hype gap+12
Incentives55
Confidence42
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On 27 and 28 September 2026, Open WebUI published a batch of at least 15 security advisories, every one of which is fixed in 0.11.4.

    ReportedSupportedSource: dev.to post by MV2 of Munim, Inc.View cited source
  2. [2]

    GHSA-vpq8-f445-hcq7 is rated High, CVSS 8.1, and affects Open WebUI 0.7.0 up to 0.11.4.

    ReportedSupportedSource: dev.to post citing Open WebUI advisoryView cited source
  3. [3]

    A user signed in to Open WebUI who visits an attacker's web page in the same browser can have that page open Open WebUI in a popup and receive the session token; a message listener accepted messages from any origin.

    ReportedSupportedSource: dev.to post citing Open WebUI advisoryView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 10, 2026

    Open WebUI before 0.11.4: any website you visit could take your session token, and your scanner won't tell you

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Self-hosted LLM interface securityFollow
  • Vulnerability databasesFollow

Entities

Loading related stories