← Πίσω στην αναζήτηση CVE

CVE-2026-70484

Περιγραφή

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator-s configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users- data. This issue is fixed in 0.11.0.

CVSS 4.3EPSS 0.267%Κίνδυνος 0.44
Προβολή πηγής
Δημοσίευση
2026-08-04 20:16:55
Τελευταία τροποποίηση
2026-08-05 16:17:02
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L