Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minute…
Medium CVSS 6.5
Summary
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of 2000-01-01 and then walked forward one interval at a time to find the next run. A single FREQ=MINUTELY rule enumerates roughly a quarter-century of occurrences synchronously on the event loop that also serves scheduler, HTTP, and WebSocket traffic, and the sche…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/open-webui/open-webui/commit/c4ae8c86786fed521960466f6d8eef8af22c2946 Patch
- https://github.com/open-webui/open-webui/releases/tag/v0.11.0 Release Notes
- https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c Exploit
- https://github.com/open-webui/open-webui/security/advisories/GHSA-73cq-mcgh-379c Exploit
Timeline
- nvd_ingest NVD