Junglewise Threat Intelligence

CVE-2025-15603: Open WebUI hardcoded JWT secret in dead code

CVE-2025-15603 · Severity: low · CVSS 3.7 · Published 2026-03-09

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

This report concerned Open WebUI, a self-hosted web interface for AI chat models, and alleged that a startup script on Windows could generate a weak secret key used for session/authentication tokens. However, the issuing organization (GitHub) formally withdrew the advisory after determining it does not represent a genuine security flaw. No action is required, and organizations should disregard this report as a confirmed risk.</exec_brief> <parameter name="technical_details">The original report described the JWT key handler in backend/start_windows.bat of open-webui (<=0.6.16), alleging that manipulation of the WEBUI_SECRET_KEY argument could result in insufficiently random values, potentially weakening JWT signing keys. The claimed CVSS 3.1 vector was AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N (score 3.7), indicating low confidentiality impact with high attack complexity and no privileges/user interaction required. However, GitHub's security team reviewed and formally withdrew this advisory, stating it "does not describe a valid vulnerability." No CWE was assigned, no patched version was published, and the entry is retained only to preserve external reference links (NVD, huntr.com, vuldb.com). Consumers of vulnerability feeds should mark this CVE as invalid/non-actionable rather than apply mitigations.</technical_details> <parameter name="severity">info

Affected products

  • open-webui open-webui <= 0.6.16

Timeline

  • 2026-03-09: disclosed: Advisory published to GitHub Advisory Database
  • 2026-09-02: other: Advisory withdrawn by GitHub as not a valid vulnerability

References

Related threats