CVE-2025-15603 | open-webui up to 0.6.16 JWT Key start_windows.bat WEBUI_SECRET_KEY random values
A vulnerability categorized as problematic has been discovered in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values.
This vulnerability is referenced as CVE-2025-15603. It is possible to launch the attack remotely. Furthermore, an exploit is available.