⚠ Withdrawn by GitHub Security Advisories
Withdrawn: September 2, 2026
GHSA-2rf6-9rc8-rqchLowCVSS 3.7
Withdrawn Advisory: Open WebUI JWT Key Handler
🔗 CVE IDs covered (1)
📋 Description
Withdrawn Advisory
This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references.
Original Description
A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.
🎯 Affected products1
- pip/open-webui:<= 0.6.16