Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-63391
CVE-2025-63391
An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
Published Jan 2, 2026
https://github.com/advisories/GHSA-hqhc-8hp4-hrwc
CVSS Score
High
7.5
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
open-webui
0.1.125
pypi
open-webui
0.1.124
pypi
open-webui
0.1.125
pypi
open-webui
0.2.0.dev1
pypi
open-webui
0.2.0.dev2
pypi
open-webui
0.2.0.dev3
pypi
open-webui
0.2.0.dev4
pypi
open-webui
0.2.0
pypi
open-webui
0.2.1
pypi
open-webui
0.2.2
pypi
open-webui
0.2.3
pypi
open-webui
0.2.4
pypi
open-webui
0.2.5
pypi
open-webui
0.3.0
pypi
open-webui
0.3.10
pypi
open-webui
0.3.11
pypi
open-webui
0.3.12
pypi
open-webui
0.3.13
pypi
open-webui
0.3.14
pypi
open-webui
0.3.15
pypi
open-webui
0.3.16
pypi
open-webui
0.3.17.dev1
pypi
open-webui
0.3.17.dev2
pypi
open-webui
0.3.17.dev3
pypi
open-webui
0.3.17.dev4
pypi
open-webui
0.3.17.dev5
pypi
open-webui
0.3.17.dev6
pypi
open-webui
0.3.17
pypi
open-webui
0.3.18
pypi
open-webui
0.3.19
pypi
open-webui
0.3.1
pypi
open-webui
0.3.20
pypi
open-webui
0.3.21
pypi
open-webui
0.3.22
pypi
open-webui
0.3.23
pypi
open-webui
0.3.24
pypi
open-webui
0.3.25
pypi
open-webui
0.3.26
pypi
open-webui
0.3.27.dev1
pypi
open-webui
0.3.27.dev2
pypi
open-webui
0.3.27.dev3
pypi
open-webui
0.3.27
pypi
open-webui
0.3.28
pypi
open-webui
0.3.29
pypi
open-webui
0.3.2
pypi
open-webui
0.3.30.dev1
pypi
open-webui
0.3.30.dev2
pypi
open-webui
0.3.30
pypi
open-webui
0.3.31.dev1
pypi
open-webui
0.3.31
1-50 of 133
CVE-2025-63391 | Components Impacted | Sonatype Guide | Sonatype Guide