PT-2026-59342 · Pypi · Open-Webui
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Affected Component
Socket.IO session state and role-check callsites:
backend/open webui/socket/main.py(lines 330-351,connecthandler — role snapshotted into SESSION POOL)backend/open webui/socket/main.py(lines 393-398,heartbeathandler — does not refresh role)backend/open webui/socket/main.py(line 538,ydoc:document:join— uses cached role for admin check)backend/open webui/socket/main.py(line 611,document save handler— uses cached role for admin check)backend/open webui/routers/users.py(lines 557-633, role update — does not invalidate SESSION POOL)backend/open webui/routers/users.py(line 641, user delete — does not invalidate SESSION POOL)
Affected Versions
Current main branch (commit
6fdd19bf1) and likely all versions with the collaborative document (Yjs) Socket.IO handlers.Description
When a user connects via Socket.IO, the
connect handler authenticates them via JWT and stores their user record (including role) in the in-memory SESSION POOL dictionary keyed by session ID. The heartbeat handler keeps the session alive indefinitely but only refreshes the last seen at timestamp — never the role.Role checks in the Yjs collaborative document handlers (
ydoc:document:join, document save handler) consult the cached SESSION POOL role rather than the database. Meanwhile, administrative role changes and user deletions do not iterate SESSION POOL to disconnect affected sessions. As a result, a user whose admin role has been revoked retains admin privileges within their existing Socket.IO session for as long as they keep the connection alive (via automatic heartbeats).HTTP endpoints are not affected —
get current user at [utils/auth.py](backend/open webui/utils/auth.py) refetches the user record from the database on every request. The gap is exclusive to the Socket.IO session cache.python
# socket/main.py:330-351 — role snapshotted at connect time
async def connect(sid, environ, auth):
user = None
if auth and 'token' in auth:
data = decode token(auth['token'])
if data is not None and 'id' in data:
user = Users.get user by id(data['id'])
if user:
SESSION POOL[sid] = {
'id': user.id,
'role': user.role, # ← snapshotted, never refreshed
...
}
# socket/main.py:393-398 — heartbeat refreshes last seen at only
async def heartbeat(sid, data):
user = SESSION POOL.get(sid)
if user:
SESSION POOL[sid] = {**user, 'last seen at': int(time.time())}
# role is carried forward unchanged
# socket/main.py:538 — admin check against cached role
if user.get('role') != 'admin' and not has access(user id, 'note', note id, 'read', db=db):
returnAttack Scenario
- User B is an admin and has an active browser session with a live Socket.IO connection.
SESSION POOL[sid]recordsrole='admin'. - Admin A demotes User B to a regular user via
POST /api/v1/users/{B id}/update. The DBuser.rolebecomes'user'. - No Socket.IO disconnect, no SESSION POOL update, no token revocation event is triggered by the role change.
- User B's client continues sending
heartbeatevents every few seconds; these are accepted and only refreshlast seen at. - User B emits
ydoc:document:joinwithdocument id = 'note:<victim note id>'for any note they do not own. - The handler at line 538 evaluates
user.get('role') != 'admin'— returnsFalsebecauseSESSION POOLstill holds the staleadminrole. Access check is bypassed, User B joins the document room, receives full document state and live updates. - User B emits
ydoc:document:updatefor the same note. The handler at line 611 performs the same cached-admin check, bypasses authorization, and persists attacker-controlled content to the victim's note viaNotes.update note by id.
The same bypass occurs if the user is deleted entirely (
delete user by id) — the deleted user retains admin privileges on their live socket until disconnection.Impact
- Read access to any user's notes after admin privileges have been revoked
- Write access (content injection, overwrite) to any user's notes under the same conditions
- The stale privilege is bounded only by the attacker's willingness to keep the Socket.IO connection alive; heartbeats extend the session indefinitely
- Official admin demotion or user deletion gives a false sense of security — HTTP access is correctly revoked, but real-time collaborative access silently continues
Preconditions
- Attacker must have an active Socket.IO connection established while they held admin role
- Attacker must retain the Socket.IO session after demotion/deletion (trivial — just don't close the browser)
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui