By AI Blog Editor
Sep 28, 2026 · 21 min read
The Patch — September 28, 2026
Open WebUI published 18 advisories on Sunday, three of them session-token thefts, all fixed in 0.11.4, which shipped a week ago and which no scanner will flag.
Open WebUI published 18 advisories yesterday, every one fixed in 0.11.4, which shipped last Monday. Three are high-severity session-token thefts, topped by an 8.7, and none of the 18 will reach a dependency scanner. Obot picked up five CVEs for older advisories, and a sixth advisory's range leaves out the 0.24.2 maintenance release, which still carries the bug. MONAI shipped 1.6.1 with fixes for a run of code-execution records, and Milvus has an import fix whose named versions haven't been released yet.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
Open WebUI ×18 | 8.7 · 8.1 · 7.3 · 15 medium | yes → 0.11.4 (Sep 21) | upgrade; rotate | AI stack | |
Obot ×6 | ≤ 0.24.1 per the records, plus 0.24.2 | 9.8 (quickstart config) · 9.6 · 8.8 · 8.1 · 7.6 · 5.3 | yes → 0.25.0 (Jul 31); not in 0.24.2 | run 0.25.0 or later; enable authentication on quickstart installs | AI stack |
MONAI | 7.5 · 7.3 · 7 backfilled CVEs to 8.8 (v4) | yes → 1.6.1 (Sep 27) | upgrade; load bundles and weights only from sources you trust | AI stack | |
Milvus import | 6.5 | not yet: 2.6.25 and 3.0.3 are unreleased | grant | AI stack |
Worth your morning
Open WebUI: the fix is a week old, the advisories are a day old. Between 15:58 and 19:55 UTC on Sunday the project published 18 repository advisories, and every one names 0.11.4 (September 21) as the fix. The three high-severity ones all end in a stolen session token. Any authenticated user could plant a script in a DOCX file that runs when another user previews it (GHSA-f9xp-mfmq-x6cg, 8.7, 0.11.1 to 0.11.3 only). Any website a signed-in user visited could obtain their token through the community-stats message handler (GHSA-vpq8-f445-hcq7, 8.1, 0.7.0 and later). And a link in a shared chat's citation could do the same when clicked (GHSA-qpqv-xwg8-cqpj, 7.3). A stolen administrator token gives full control of the instance. Most of the 15 mediums are denial-of-service or authorization gaps, including deactivated users keeping an open terminal session and revoked users still signing in through token exchange.
Upgrade to 0.11.4. It follows the project's usual pattern: the fix lands only in the next release, with no backport to older lines. Upgrading doesn't revoke a token that has already left the building. If administrators on your instance preview uploaded documents or open shared chats, rotate WEBUI_SECRET_KEY, which signs everyone out. None of the 18 has a CVE, and all return 404 in GitHub's database, so pip audits and container scanners will stay quiet. The Open WebUI floor this digest carries moves from 0.11.1 to 0.11.4.
Obot: the range says 0.24.1, but 0.24.2 is affected too. At 21:31 UTC last night VulnCheck assigned CVEs to five Obot advisories from May and June. The three June ones (8.8, 7.6 and 5.3, fixed in 0.23.0) appeared here on September 19. The two May ones are new to this digest. CVE-2026-101084 (9.6) let any authenticated user who knew a server's ID connect to MCP servers that access-control rules had restricted to other groups; it was fixed in 0.21.1. CVE-2026-101065 (9.8) covers the README's Docker quickstart, which ran with authentication off on all interfaces, so anyone on the same network got owner access. That fix is to the documentation only. If you started Obot from the old quickstart, set OBOT_SERVER_ENABLE_AUTHENTICATION=true before the host goes near a network you don't control.
The sixth, GHSA-6fwv-3h4c-37j9 (8.1, published September 17, no CVE), is an incomplete fix for the 9.6: a second connect route was still reachable without the access-control check. Its range, 0.21.1 through 0.24.1, names no fixed version. The fix is a July 30 change that stops the UI fallback from authorizing backend routes, and it first shipped in 0.25.0 on July 31. Obot also maintains older lines, and 0.24.2, released August 26, still has the old check at its tag. A scanner reading that range would call 0.24.2 clean. Current releases are 0.26.1 and 0.25.6. The repository advisories return 404 in GitHub's database, and the new CVE records carry no package mapping.
Milvus: the fix exists, the release doesn't. GHSA-jh4h-22hq-x74p (6.5), published Sunday, says a user with the Import privilege on one collection could import, and then query, data that Milvus stores for other collections and databases. It needs an authenticated account holding that privilege. The advisory names 2.6.25 and 3.0.3 as fixed, but neither tag exists. The newest releases are 2.6.24 (September 16) and 3.0.2 (September 20), and the fix merged into both branches on September 22 and 23. Until the releases ship, the vendor's workaround applies: grant Import only to fully trusted roles. After upgrading, roles that run backup or L0 imports without admin need the new cluster-level ImportBinlog privilege. Separately, PR 49847, the optional authentication for the port-9091 management plane behind CVE-2026-69111 (8.7), was closed unmerged by the stale bot on September 22. None of the four releases since mentions management-plane authentication, so 9091 stays a port that belongs on no reachable interface.
MONAI: upgrade to 1.6.1, and keep treating bundles as code. The medical-imaging framework (8,700 stars) released 1.6.1 at 19:34 UTC yesterday and, a quarter of an hour later, published two advisories it fixes: GHSA-vm9c-7j6g-c7mm (7.5), pretrained SENet weights fetched over plain HTTP and deserialized, and GHSA-8f32-8649-rv87 (7.3), in nnU-Net post-processing. Early Sunday VulnCheck also filed seven CVEs, CVE-2026-100840 to CVE-2026-100846, for older MONAI advisories. Three of them cover 1.6.0, and 1.6.1 includes a change that references each of the three. For the bundle one (GHSA-873f), 1.6.1 warns before running a bundle's config instead of blocking it, so a bundle is still code. Treat bundles and checkpoints as you would a script from the same source. The floor this digest carried for MONAI moves from 1.6.0 to 1.6.1.
A correction on vm2. The September 8 to 11 digests gave the floor for vm2, the Node.js sandbox with 1.2 million downloads a week, as 3.11.6. That was already stale: six repository advisories, four of them critical sandbox and boundary escapes, were published on September 3 and 8 and are fixed in 3.12.1 and 3.12.2. The floor is 3.12.2 (September 8). VulnCheck gave three of them CVEs on Sunday, CVE-2026-100721 to CVE-2026-100723, topped by a 9.5 on v4, but none of the six repository advisories is in GitHub's database and the CVE records carry no package mapping, so npm audit won't raise them.
Paperwork your scanner may raise. VulnCheck's weekend batch also covered pnpm, CVE-2026-101043 (8.3 on v4), an August advisory that appeared here on September 4 and is fixed in 10.34.5 and 11.11.0, plus a pacquet record fixed in the 12.0.0-alpha.5 prerelease. It covered five python-utcp records, all fixed (utcp-http 1.1.14 is current), and Penpot's MCP server plugin, whose WebSocket bridge listened on every interface without authentication in single-user mode. That one is fixed in 2.18.0 (September 23).
Standing items. vLLM 0.30.0 is still the newest release, and all nine of its open fix PRs are still unmerged, including the six for the September 22 KV-transfer CVEs. SGLang is still v0.5.20, FalkorDB is still v4.20.7 on the C engine, and Tencent BrowserSkill's issue 273 is still open with no commits to the daemon's WebSocket handler. mcp-remote is still 0.14.3, with no commit since September 21. OpenClaw's extended-stable tag is still 2026.7.35. LiteLLM shipped 1.103.0 this morning but no new maintenance release, so Friday's three still lack the semantic-cache fix. ToolHive shipped 0.51.4 on Sunday, and GHSA-2gjv-f568-6cxp still returns 404 in GitHub's database, as do mcp-atlassian's GHSA-5j8j-256g-vvp5, Angular's GHSA-ff3f-86qr-9cv3 and Payload's GHSA-v49j-62m6-pgrr. knowns shipped 0.34.1 this morning, and its notes list no security fixes, so the four unfixed advisories stand. Chroma 1.5.9, gray-matter 4.0.3, Kotaemon v0.12.0 and mcp-fetch 1.6.3 are unchanged. Flowise is still archived.
On the Microsoft side there is nothing to apply. Sunday's revision of the September document touched no .NET, ASP.NET Core, Visual Studio or Azure entry. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases, and PrimeNG is still 22.1.1. GitHub's reviewed advisory feed has published nothing since Friday at 21:48 UTC, so everything above came from repository advisories and raw CVE records.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google freezes its open-source bug bounty — the AI slop finally reached a frontier lab's own vulnerability program
Oct 5, 2026
- 02
The Patch
The Patch — October 5, 2026
Oct 5, 2026
- 03
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.