Description

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.

INFO

Published Date :

2025-12-04T00:00:00.000Z

Last Modified :

2025-12-05T19:51:31.248Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63681 vulnerability.

Vendors Products
Open-webui
  • Open-webui
Openwebui
  • Open Webui

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact