Authentication Bypass Vulnerability in Open-WebUI by Open-WebUI
CVE-2025-63391
7.5HIGH
What is CVE-2025-63391?
An authentication bypass vulnerability has been identified in Open-WebUI version 0.6.32 and earlier versions. This issue arises from insufficient authentication and authorization mechanisms at the /api/config endpoint, allowing unauthenticated remote attackers to access sensitive system configuration data. The flaw puts users at risk, as it potentially exposes critical information that should remain secured from unauthorized access.
