CVE-2026-45365 | open-webui Open WebUI up to 0.8.10 HTTP Endpoint /openai/chat/completions bypass_filter improper authorization (GHSA-v6qf-75pr-p96m)
A vulnerability was found in open-webui Open WebUI up to 0.8.10 and classified as critical. Affected by this vulnerability is the function bypass_filter of the file /openai/chat/completions of the component HTTP Endpoint. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-45365. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.