Information disclosure in Open WebUI - #VU140755
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the tool read endpoints when handling requests for shared tools. A remote user can call the affected endpoints to disclose sensitive information.
Authentication and enabled plugins are required, and the issue affects tools shared with read access where the caller does not have write access.