id: PYSEC-2026-1732 summary: open-webui is Vulnerable to Incorrect Access Control details: open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks. aliases: - CVE-2025-63681 - GHSA-frv8-gffc-37px modified: '2026-07-23T09:44:32.769134Z' published: '2026-07-07T16:03:12.102402Z' references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-63681 - type: WEB url: https://github.com/TOAST-Research/pocs/blob/main/openwebui/arbitirary_task_stop/report.md - type: PACKAGE url: https://github.com/open-webui/open-webui - type: WEB url: https://github.com/open-webui/open-webui/blob/46ae3f4f5d7d4d706041bdae4ad2d802e568712b/backend/open_webui/main.py#L1652 - type: PACKAGE url: https://pypi.org/project/open-webui - type: ADVISORY url: https://github.com/advisories/GHSA-frv8-gffc-37px - type: FIX url: https://github.com/open-webui/open-webui/commit/e7ff4768f8ffe1924b4576381c9e45e8a64350e4 affected: - package: name: open-webui ecosystem: PyPI purl: pkg:pypi/open-webui ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: 0.9.0 versions: - 0.1.124 - 0.1.125 - 0.2.0 - 0.2.1 - 0.2.2 - 0.2.3 - 0.2.4 - 0.2.5 - 0.3.0 - 0.3.1 - 0.3.10 - 0.3.12 - 0.3.13 - 0.3.14 - 0.3.15 - 0.3.16 - 0.3.17 - 0.3.17.dev2 - 0.3.17.dev3 - 0.3.17.dev4 - 0.3.17.dev5 - 0.3.18 - 0.3.19 - 0.3.2 - 0.3.20 - 0.3.21 - 0.3.22 - 0.3.23 - 0.3.24 - 0.3.25 - 0.3.26 - 0.3.27 - 0.3.27.dev1 - 0.3.27.dev2 - 0.3.27.dev3 - 0.3.28 - 0.3.29 - 0.3.3 - 0.3.30 - 0.3.30.dev1 - 0.3.30.dev2 - 0.3.31 - 0.3.31.dev1 - 0.3.32 - 0.3.33 - 0.3.33.dev1 - 0.3.34 - 0.3.35 - 0.3.4 - 0.3.5 - 0.3.6 - 0.3.7 - 0.3.8 - 0.3.9 - 0.4.0 - 0.4.0.dev1 - 0.4.0.dev2 - 0.4.1 - 0.4.2 - 0.4.3 - 0.4.4 - 0.4.5 - 0.4.6 - 0.4.6.dev1 - 0.4.7 - 0.4.8 - 0.5.0 - 0.5.0.dev1 - 0.5.0.dev2 - 0.5.1 - 0.5.10 - 0.5.11 - 0.5.12 - 0.5.13 - 0.5.14 - 0.5.15 - 0.5.16 - 0.5.17 - 0.5.18 - 0.5.19 - 0.5.2 - 0.5.20 - 0.5.3 - 0.5.3.dev1 - 0.5.4 - 0.5.5 - 0.5.6 - 0.5.7 - 0.5.8 - 0.5.9 - 0.6.0 - 0.6.1 - 0.6.10 - 0.6.11 - 0.6.12 - 0.6.13 - 0.6.14 - 0.6.15 - 0.6.16 - 0.6.18 - 0.6.19 - 0.6.2 - 0.6.20 - 0.6.21 - 0.6.22 - 0.6.23 - 0.6.24 - 0.6.25 - 0.6.26 - 0.6.26.dev1 - 0.6.27 - 0.6.28 - 0.6.29 - 0.6.3 - 0.6.30 - 0.6.31 - 0.6.32 - 0.6.33 - 0.6.4 - 0.6.5 - 0.6.6 - 0.6.6.dev1 - 0.6.7 - 0.6.8 - 0.6.9 - 0.6.34 - 0.6.35 - 0.6.36 - 0.6.37 - 0.6.38 - 0.6.39 - 0.6.40 - 0.6.41 - 0.6.42 - 0.6.43 - 0.7.0 - 0.7.1 - 0.7.2 - 0.8.0 - 0.8.1 - 0.8.10 - 0.8.11 - 0.8.12 - 0.8.2 - 0.8.3 - 0.8.4 - 0.8.5 - 0.8.6 - 0.8.7 - 0.8.8 - 0.8.9 severity: - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P