CVE-2026-45396 | open-webui WebUI up to 0.9.4 feedback insert_new_feedback server-derived dynamically-determined object attributes (GHSA-rjmp-vjf2-qf4g)
A vulnerability was found in open-webui WebUI up to 0.9.4. It has been classified as problematic. Affected by this issue is the function insert_new_feedback of the file /api/v1/evaluations/feedback. Performing a manipulation of the argument server-derived results in dynamically-determined object attributes.
This vulnerability is cataloged as CVE-2026-45396. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.