chiprook
← Security
SecurityOctober 11, 2026, 11:26

Open WebUI before 0.11.4: any site could steal your session token

On 27–28 September 2026 Open WebUI published at least 15 security advisories, all fixed in 0.11.4. The key flaw GHSA-vpq8-f445-hcq7 (High, CVSS 8.1) lets an attacker's page grab a signed-in user's session token via a popup when ENABLE_COMMUNITY_SHARING is on. None of the advisories has a CVE ID and they are missing from the GitHub Advisory Database and OSV, so dependency scanners report affected versions as clean.

Open WebUI before 0.11.4: any site could steal your session token
#OpenWebUI#Ollama
Read next
Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Security

CSuite phishing steals Microsoft 365 sessions, deploys RMM tools

Security

Fake ChatGPT, Gemini sites steal ad accounts and MFA codes

Security

Malicious AI agents steal 600K credit cards, infect 119 sites with skimmers