CVE-2025-15603Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The vendor explains: "The 't0p-s3cr3t' default was dead code on every supported startup path: start.sh, start_windows.bat and `open-webui serve` all set or auto-generate WEBUI_SECRET_KEY before the backend imports env.py. It was only ever reachable by invoking uvicorn directly, which is unsupported and unsafe (the app would then sign tokens/cookies with a public, hardcoded key)."

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-09: 2Technical Details · 2026-03-09: 203-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15603 Open-WebUI JWT Key Handler Vulnerability Enables Weak Secret Key Generation https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15603

    Post summary

    CVE-2025-15603 reveals a flaw in Open‑WebUI's JWT key handler enabling the generation of weak secret keys, and a vulnerability details page is linked for more information.

    0000085
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15603 A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key … https://www.cve.org/CVERecord?id=CVE-2025-15603

    Post summary

    A new CVE has been identified in open‑webui up to version 0.6.16, affecting an unknown function in backend/start_windows.bat of the JWT Key component; no PoC, exploit code, or patch information is provided.

    0000091
    56.6K followersView on X

Explore more