Known CVE
Open WebUI < 0.9.5 - Information Disclosure
Open WebUI < 0.9.5 contains an information disclosure vulnerability caused by unauthenticated access to GET /api/v1/retrieval/ endpoint, letting remote attackers retrieve live RAG pipeline configuration without authorization, exploit requires no authentication.
CVE-2026-45397
Medium2026CVSS 5.3CWE-862
cve2026 · open-webui · exposure · misconfig
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website