8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-45672 Overview The Open WebUI platform, designed for offline operation, contains a security flaw allowing verified users to execute arbitrary Python code via the /api/v1/utils/code/execute endpoint, even if code execution is disabled in the...
Basic Information
ID
C3B7D1E4-96DB-5CE7-92A6-AAA6AB6084FE
Published
May 16, 2026 at 02:36
Modified
May 16, 2026 at 02:39