Information disclosure in Open WebUI - #VU152704

 

Information disclosure in Open WebUI - #VU152704

Published: September 28, 2026


Vulnerability identifier: #VU152704
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose tool source code and embedded sensitive information.

The vulnerability exists due to improper authorization in the GET /api/v1/tools/export endpoint when exporting tools shared with the user with read-only access. A remote user can request a bulk tool export to disclose tool source code and embedded sensitive information.

The issue occurs when plugins are enabled.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.4

External References

Related Security Bulletins