CVE-2025-63681
open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
Vendor
Product
CWE
Yayın Tarihi
2025-12-04 16:16:22
Güncelleme
2025-12-05 20:15:57
Source Identifier
cve@mitre.org
KEV Date Added
-