open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Open_webui | Openwebui | 0.6.41 (including) | 0.6.41 (including) |