Vulnerability Description
A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/b9fc7fee-d25d-4100-9703-5e78a61e1ce4
- https://vuldb.com/?ctiid.349701
- https://vuldb.com/?id.349701
- https://vuldb.com/?submit.766444
FAQ
What is CVE-2025-15603?
CVE-2025-15603 is a vulnerability with a CVSS score of 3.7 (LOW). A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the ...
How severe is CVE-2025-15603?
CVE-2025-15603 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-15603?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.