CRITICAL
GHSASUPPLY-CHAINCVE-2025-8943LLM05:2025 Supply Chain Vulnerabilities
2026-08-04
Unauthenticated attackers can bypass the patch and force npx to install and run arbitrary packages, leading to remote code execution.
2026-08-04
Authenticated users can use server-side fetch to access internal services or cloud metadata and read sensitive responses.
2026-08-04
Read-only users can access server-side tool code, exposing embedded secrets and internal logic.
2026-08-04
A user can make the browser fetch internal URLs and leak internal data back through web-search or RAG output.
2026-08-04
A logged-in attacker can bypass URL checks and make the app fetch internal resources, exposing data from private network services.
2026-08-04
An attacker can make a victim's browser send network requests and read some responses, exposing internal or trusted resources.
2026-08-04
Pending or deactivated users can bypass approval checks and get interactive terminal access if a terminal server is exposed to them.
2026-08-04
Stored XSS can hijack viewer sessions and let a normal user take over admin accounts in Open WebUI.
2026-08-04
An authenticated user can run script in the app origin and steal session tokens, leading to account takeover where terminal preview is enabled.
2026-08-04
A low-privilege user may freeze the single worker event loop and disrupt HTTP, WebSocket, and scheduler availability.
2026-08-04
A user with limited access can delete another knowledge base's directories and embeddings, breaking integrity across shared data.
2026-08-04
Revoked users can still trigger server-side image generation, bypassing intended access controls under specific configuration.