A AegiFlow
LOWCVSS 2.9EPSS 0.0%

CVE-2025-15603

Withdrawn Advisory: Open WebUI JWT Key Handler

Published
2026-03-09
Modified
2026-09-02
EPSS percentile
14%
Aliases
GHSA-2rf6-9rc8-rqch
Sources
github-advisory

Summary

### Withdrawn Advisory This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references. ### Original Description A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.