Missing Authorization in Open WebUI - #VU152706
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to add chats to a shared folder after their write access has been revoked.
The vulnerability exists due to missing authorization in the chat fork handler in `backend/open_webui/routers/chats.py` when forking a previously created chat through `POST /api/v1/chats/{id}/fork`. A remote user can fork a chat created while they had write access to add chats to a shared folder after their write access has been revoked.
Exploitation requires that the user was previously granted write access to the shared folder, created a chat there, and was later downgraded to read-only access.