CVE-2025-63391
Open-WebUI Authentication Bypass Vulnerability
Description
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
INFO
Published Date :
Dec. 18, 2025, 4:15 p.m.
Last Modified :
June 29, 2026, 8:17 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Solution
- Update Open-WebUI to the latest version.
- Ensure API endpoints have proper authentication.
- Review and implement access controls.
Public PoC/Exploit Available at Github
CVE-2025-63391 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
A project tracking CVEs exploited in the wild affecting AI-related products and infrastructure
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-63391 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2025-63391 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Rejected by [email protected]
Jun. 29, 2026
Action Type Old Value New Value -
CVE Modified by [email protected]
Jun. 29, 2026
Action Type Old Value New Value Changed Description An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. Removed CVSS V3.1 CISA-ADP: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Removed CWE CISA-ADP: CWE-306 Removed CPE Configuration OR *cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* versions up to (including) 0.6.32 Removed Reference MITRE: https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b Removed Reference MITRE: https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c Removed Reference MITRE: https://github.com/open-webui/open-webui/issues Removed Reference Type MITRE: https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b Types: Third Party Advisory Removed Reference Type MITRE: https://github.com/open-webui/open-webui/issues Types: Issue Tracking Removed Affected [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}] Removed SSVC {'id': 'CVE-2025-63391', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-12-18T17:50:17.975164Z'} -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'n/a', 'product': 'n/a', 'versions': [{'status': 'affected', 'version': 'n/a'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2025-63391', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2025-12-18T17:50:17.975164Z'} -
CVE Modified by [email protected]
Jan. 22, 2026
Action Type Old Value New Value Added Reference https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c -
Initial Analysis by [email protected]
Dec. 30, 2025
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:* versions up to (including) 0.6.32 Added Reference Type MITRE: https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b Types: Third Party Advisory Added Reference Type MITRE: https://github.com/open-webui/open-webui/issues Types: Issue Tracking -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Dec. 18, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Added CWE CWE-306 -
New CVE Received by [email protected]
Dec. 18, 2025
Action Type Old Value New Value Added Description An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers. Added Reference https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b Added Reference https://github.com/open-webui/open-webui/issues