An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b | Third Party Advisory |
| https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c | |
| https://github.com/open-webui/open-webui/issues | Issue Tracking |
Configurations
History
22 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Dec 2025, 19:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b - Third Party Advisory | |
| References | () https://github.com/open-webui/open-webui/issues - Issue Tracking | |
| First Time |
Openwebui open Webui
Openwebui |
|
| CPE | cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* |
18 Dec 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-306 |
18 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 16:15
Updated : 2026-01-22 18:16
NVD link : CVE-2025-63391
Mitre link : CVE-2025-63391
CVE.ORG link : CVE-2025-63391
JSON object : View
Products Affected
openwebui
- open_webui
CWE
CWE-306
Missing Authentication for Critical Function
