Vulnerability Description
An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | <= 0.6.32 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51bThird Party Advisory
- https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c
- https://github.com/open-webui/open-webui/issuesIssue Tracking
FAQ
What is CVE-2025-63391?
CVE-2025-63391 is a vulnerability with a CVSS score of 7.5 (HIGH). An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configu...
How severe is CVE-2025-63391?
CVE-2025-63391 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63391?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.