CVE-2025-63681 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, ena…
Medium CVSS: 4.3

CVE-2025-63681

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
Vendor
Openwebui
Product
Open Webui
CWE
NVD-CWE-noinfo
Yayın Tarihi
2025-12-04 16:16:22
Güncelleme
2025-12-05 20:15:57
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar