An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b | Third Party Advisory |
| https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c | |
| https://github.com/open-webui/open-webui/issues | Issue Tracking |
Configurations
History
No history.
Information
Published : 2025-12-18 16:15
Updated : 2026-01-22 18:16
NVD link : CVE-2025-63391
Mitre link : CVE-2025-63391
CVE.ORG link : CVE-2025-63391
JSON object : View
Products Affected
openwebui
- open_webui
CWE
CWE-306
Missing Authentication for Critical Function
