CVE-2025-63391
An authentication bypass vulnerability exists in Open-WebUI <=0.6.32 in the /api/config endpoint. The endpoint lacks proper authentication and authorization controls, exposing sensitive system configuration data to unauthenticated remote attackers.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://gist.github.com/Cristliu/889471313b3c698fff74d32b7717807c, https://gist.github.com/Cristliu/13c41b97285b776275bc8bfd3504e51b, https://github.com/open-webui/open-webui/issues
