Open WebUI before 0.11.4: any site could steal your session token
On 27–28 September 2026 Open WebUI published at least 15 security advisories, all fixed in 0.11.4. The key flaw GHSA-vpq8-f445-hcq7 (High, CVSS 8.1) lets an attacker's page grab a signed-in user's session token via a popup when ENABLE_COMMUNITY_SHARING is on. None of the advisories has a CVE ID and they are missing from the GitHub Advisory Database and OSV, so dependency scanners report affected versions as clean.
- GHSA-vpq8-f445-hcq7: CVSS 8.1, affects versions 0.7.0–0.11.4
- Attack runs through the browser; LAN or VPN exposure doesn't help
- Advisories without CVE IDs are absent from GitHub Advisory Database and OSV
- Current release is 0.12.0, published 10 October 2026
Read next
Security