SB20260928431 - Multiple vulnerabilities in Open WebUI
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Information disclosure (CVE-ID: N/A)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose tool source code and embedded sensitive information.
The vulnerability exists due to improper authorization in the GET /api/v1/tools/export endpoint when exporting tools shared with the user with read-only access. A remote user can request a bulk tool export to disclose tool source code and embedded sensitive information.
The issue occurs when plugins are enabled.
2) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to retain access to resources permitted by their existing role.
The vulnerability exists due to incorrect authorization in the OAuth token exchange endpoint and OAuth role policy when exchanging a provider access token for an Open WebUI session. A remote user can exchange a valid provider access token after their provider role no longer satisfies the allowed-role policy to retain access to resources permitted by their existing role.
Exploitation requires OAuth token exchange and OAuth role management to be enabled, an allowed-role configuration that does not contain a wildcard, a provider that supplies roles only in the ID token, and a previously linked account.
3) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to add chats to a shared folder after their write access has been revoked.
The vulnerability exists due to missing authorization in the chat fork handler in `backend/open_webui/routers/chats.py` when forking a previously created chat through `POST /api/v1/chats/{id}/fork`. A remote user can fork a chat created while they had write access to add chats to a shared folder after their write access has been revoked.
Exploitation requires that the user was previously granted write access to the shared folder, created a chat there, and was later downgraded to read-only access.
4) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose file contents and delete files.
The vulnerability exists due to incorrect authorization in the has_access_to_file access-control function when handling file-content and delete requests for files removed from knowledge bases. A remote user can request file content or delete a file using a known file ID to disclose file contents and delete files.
Exploitation requires that the file was last processed into the shared knowledge base, remains on the instance after removal, and that the owner removes it from that knowledge base.
5) Insufficient Session Expiration (CVE-ID: N/A)
CWE-ID: CWE-613 - Insufficient Session Expiration
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute commands on the terminal server after account deactivation.
The vulnerability exists due to insufficient session expiration in the terminal proxy WebSocket route when using an already open terminal WebSocket after the user's access is withdrawn. A remote user can send commands through the existing terminal connection to execute commands on the terminal server after account deactivation.
A terminal server must be configured, the user must have been granted access to it, and the terminal session must be open when the user's role is changed to pending.
6) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to steal session tokens and gain administrative control of the instance.
The vulnerability exists due to improper neutralization of input during web page generation in the DOCX preview component when rendering a crafted DOCX attachment in Preview view. A remote user can upload a crafted DOCX document containing active content to execute script in the viewer's authenticated browser session and steal the viewer's session token.
User interaction is required to open a shared chat, open the attachment, and switch to Preview view.
7) Origin validation error (CVE-ID: N/A)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain full API access as the victim.
The vulnerability exists due to an origin validation error in the community stats message handler when processing cross-origin verify:chat messages. A remote attacker can send a crafted verify:chat message with a path-traversal chat ID to gain full API access as the victim.
Exploitation requires community sharing to be enabled and a signed-in victim to visit an attacker-controlled page that opens Open WebUI in a popup.
8) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose directory structure information from inaccessible knowledge bases.
The vulnerability exists due to authorization bypass through a user-controlled key in knowledge base directory handling endpoints when submitting a directory id from a different knowledge base. A remote user can send a request containing a foreign directory id to disclose directory structure information from inaccessible knowledge bases.
Exploitation requires knowledge of a directory id in a knowledge base to which the user does not have access.
9) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to access victim accounts with their full permissions.
The vulnerability exists due to improper neutralization of input during web page generation in the chat markdown link renderer when rendering a markdown link with a javascript: URL that a victim clicks. A remote user can share a chat containing a markdown link with a javascript: URL to access victim accounts with their full permissions.
WebKit browsers execute the URL on a plain click, while Firefox requires a middle click or a Ctrl/Shift click; Chromium-based browsers do not execute it.
10) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in another user's session.
The vulnerability exists due to improper neutralization of input during web page generation in the Citations.svelte showSourceModal citation click handler when a victim opens a shared read-only chat and clicks a citation. A remote user can store a javascript: URL in a chat citation and share the chat to execute arbitrary script in another user's session.
Only the citation-embed click path is affected.
11) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to manage terminal policies and other users' terminals.
The vulnerability exists due to missing authorization in the terminal proxy endpoint in backend/open_webui/routers/terminals.py when forwarding requests to Terminals administrator API paths. A remote user can send requests for administrator API paths through the terminal proxy to manage terminal policies and other users' terminals.
Exploitation requires access to an unpinned Terminals connection configured with bearer authentication.
Remediation
Install update from vendor's website.
References
- https://github.com/open-webui/open-webui/security/advisories/GHSA-2h26-836q-4jh2
- https://github.com/open-webui/open-webui/security/advisories/GHSA-2rr4-q6pg-m5g3
- https://github.com/open-webui/open-webui/security/advisories/GHSA-6fjc-5cg3-mgvh
- https://github.com/open-webui/open-webui/security/advisories/GHSA-9cxp-636w-4997
- https://github.com/open-webui/open-webui/security/advisories/GHSA-6g45-8g27-fh8q
- https://github.com/open-webui/open-webui/commit/e8bd0661d
- https://github.com/open-webui/open-webui/security/advisories/GHSA-f9xp-mfmq-x6cg
- https://github.com/open-webui/open-webui/security/advisories/GHSA-vpq8-f445-hcq7
- https://github.com/open-webui/open-webui/security/advisories/GHSA-jx3w-3pqq-7f3w
- https://github.com/open-webui/open-webui/commit/a9541c18c
- https://github.com/open-webui/open-webui/security/advisories/GHSA-wf9m-46cp-c6h6
- https://github.com/open-webui/open-webui/security/advisories/GHSA-qpqv-xwg8-cqpj
- https://github.com/open-webui/open-webui/security/advisories/GHSA-q46m-r89w-j74p
- https://github.com/open-webui/open-webui/commit/51bb8cb142f72503e861eeee25ae4dc73c26c36b