Openwebui Open Webui — CVE-2026-59214 (Critical)

Date Jul 9, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Openwebui · Open Webui
CVE CVE-2026-59214
Critical vendor advisory CVE-2026-59214

Summary

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and execute server-side code through configured tools. This issue is fixed in version 0.10.0.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 7.3) in Openwebui Open Webui. Patch or mitigate promptly. EPSS percentile: 16%.

Operator check

Review CVE-2026-59214 in your asset inventory. Apply patches per vendor guidance and verify Open Webui is not exposed. CVSS score: 7.3. EPSS probability: 0.2%; percentile: 16%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.