Impact
Open WebUI accepted non‑numeric values for the calendar event field "alert_minutes" without validating its type. When a malformed value was stored, the shared upcoming‑event scheduler raised an exception and aborted the instance‑wide alert pass, causing all users’ reminders to be suppressed while the event remained in the lookahead window. The weakness is a flaw in input validation (CWE‑754) that leads to a denial of alert service for all authenticated users.
Affected Systems
The issue affects the open‑webui:open-webui platform from version 0.9.0 through 0.11.1. Users running any of these releases with calendar permissions are vulnerable. The vulnerability is fixed in release 0.11.1.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires authenticated access with calendar permissions, so an attacker must be able to log in to the instance. Once authenticated, the attacker can inject a non‑numeric alert value and cause the alert suppression for all users. Because it does not facilitate code execution or data exfiltration, the impact is primarily operational disruption rather than a data breach.
OpenCVE Enrichment