
CVE-2026-45402 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id a… https://www.cve.org/CVERecord?id=CVE-2026-45402
Post summary
A new CVE (CVE‑2026‑45402) affecting Open WebUI before version 0.9.5 is disclosed; it notes that user‑supplied file_id parameters are accepted on multiple endpoints, but no PoC, exploit code, or mitigation details are provided.
