CVE-2026-0765
UnknownEPSS 1.60%
Last modified
This CVE is reserved or rejected; no details have been published by NVD.
Description
Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0765
Metrics
Timeline
- Published
- Last Modified
- Status
- Rejected
Related CVEs from 2026
- CVE-2026-0759Katana Network Development Starter Kit executeCommand Comman…9.8
- CVE-2026-0760Foundation Agents MetaGPT deserialize_message Deserializatio…9.8
- CVE-2026-0761Foundation Agents MetaGPT actionoutput_str_to_mapping Code I…9.8
- CVE-2026-0762GPT Academic stream_daas Deserialization of Untrusted Data R…8.1
- CVE-2026-0763GPT Academic run_in_subprocess_wrapper_func Deserialization …9.8
- CVE-2026-0764GPT Academic upload Deserialization of Untrusted Data Remote…9.8
- CVE-2026-0766Rejected reason: Open WebU's investigation further investiga…
- CVE-2026-0767Rejected reason: Open WebU's investigation showed that this …
- CVE-2026-0768Langflow code Code Injection Remote Code Execution Vulnerabi…9.8
- CVE-2026-0769Langflow eval_custom_component_code Eval Injection Remote Co…9.8
- CVE-2026-0770Langflow exec_globals Inclusion of Functionality from Untrus…9.8
- CVE-2026-0771Langflow PythonFunction Code Injection Remote Code Execution…7.1
Are you affected by CVE-2026-0765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
