CyberRota Analysis
AI-GeneratedThe Open WebUI platform is vulnerable due to improper type validation in the calendar event scheduling feature, allowing authenticated users with calendar permissions to input non-numeric values for the alert_minutes parameter. This misconfiguration can lead to the suppression of reminders for all users, as the system may abort the alert process entirely. Organizations using versions 0.9.0 to 0.11.1 should prioritize upgrading to version 0.11.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1.