⚠ Withdrawn by GitHub Security Advisories

Withdrawn: September 2, 2026

GHSA-2rf6-9rc8-rqchLowCVSS 3.7

Withdrawn Advisory: Open WebUI JWT Key Handler

Published
March 9, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Withdrawn Advisory

This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references.

Original Description

A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

🎯 Affected products1

  • pip/open-webui:<= 0.6.16

🔗 References (6)