Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the folder tree walks used by DELETE /api/v1/folders/{id} and POST /api/v1/folders/{id}/read did not track visited folder identifiers. An authenticated user could persist a parent cycle and start a request that consumed CPU and memory indefinitely, with the condition remaining stored until repaired. This issue is fixed in version 0.11.1.
References
| Link | Resource |
|---|---|
| https://github.com/open-webui/open-webui/commit/23b3a69bc26839bfa74edd1be6bfa2568ae902f4 | Patch |
| https://github.com/open-webui/open-webui/pull/28748 | Issue Tracking Patch |
| https://github.com/open-webui/open-webui/releases/tag/v0.11.1 | Release Notes |
| https://github.com/open-webui/open-webui/security/advisories/GHSA-8r35-5x5r-hv74 | Exploit Vendor Advisory |
| https://github.com/open-webui/open-webui/security/advisories/GHSA-8r35-5x5r-hv74 | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-09 21:17
Updated : 2026-09-15 16:09
NVD link : CVE-2026-87013
Mitre link : CVE-2026-87013
CVE.ORG link : CVE-2026-87013
JSON object : View
Products Affected
openwebui
- open_webui
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
