In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade open-webui to version 0.9.0 or higher.
open-webui is an Open WebUI
Affected versions of this package are vulnerable to Missing Authorization in the generate_completion, embed, embeddings, and show_model_info functions. An attacker can access restricted model information and consume compute resources by sending crafted API requests to unprotected endpoints. This is only exploitable if Ollama is configured as a backend, model access control is enabled, and the attacker knows the restricted model name.