SCA: security update for open-webui (GHSA-855v-hq7w-jmjw)

high Tenable Self-Hosted Container Security Plugin ID 445249

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before
0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal
websocket first-message authentication used decode_token without the Redis-backed is_valid_token
revocation check, allowing revoked JWTs to continue authenticating realtime connections. This issue is
fixed in version 0.10.0. (CVE-2026-59219)

Solution

Update the open-webui library and its related packages to version 0.10.0 or later.

See Also

https://github.com/advisories/GHSA-855v-hq7w-jmjw

Plugin Details

Severity: High

ID: 445249

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 7/24/2026

Updated: 7/24/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 52.02

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-59219

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/24/2026

Vulnerability Publication Date: 7/9/2026

Reference Information

CVE: CVE-2026-59219

cwe: CWE-613