A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. | |
| Title | open-webui JWT Key start_windows.bat random values | |
| Weaknesses | CWE-310 CWE-330 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-09T20:32:06.017Z
Reserved: 2026-03-07T17:27:05.310Z
Link: CVE-2025-15603
No data.
Status : Received
Published: 2026-03-09T21:16:09.580
Modified: 2026-03-09T21:16:09.580
Link: CVE-2025-15603
No data.
OpenCVE Enrichment
No data.