PT-2026-59374 · Pypi · Open-Webui
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Deactivated Channel Members Retain Full Access to Group/DM Channels
Affected Component
Channel membership authorization check:
backend/open webui/models/channels.py(lines 663-673,is user channel member)- Used at 15 locations in
backend/open webui/routers/channels.py
Affected Versions
Current main branch (commit
6fdd19bf1) and likely all versions with the group/DM channel feature.Description
The
is user channel member function checks whether a ChannelMember row exists but does not check the is active field. When a user is deactivated from a group or DM channel (removed by the channel owner, or leaves voluntarily), their membership row persists with is active=False and status='left'. Because the authorization check ignores this field, the deactivated user retains full read and write access to the channel via direct API calls.The channel correctly disappears from the deactivated user's channel list (the listing query at
get channels by user id properly filters on is active), but all 15 message-level endpoints in the router rely on is user channel member for authorization, which does not filter on is active.python
# models/channels.py:663 — missing is active check
def is user channel member(self, channel id, user id, db=None):
membership = db.query(ChannelMember).filter(
ChannelMember.channel id == channel id,
ChannelMember.user id == user id,
).first()
return membership is not None # True even when is active=FalseCompare with
get channel by id and user id (line 778) which correctly checks ChannelMember.is active.is (True).CVSS 3.1 Breakdown
| Metric | Value | Rationale |
|---|---|---|
| Attack Vector | Network (N) | Exploited remotely via API calls |
| Attack Complexity | Low (L) | No special conditions beyond knowing the channel ID (which the user had as a former member) |
| Privileges Required | Low (L) | Requires a valid user account and prior channel membership |
| User Interaction | None (N) | No victim interaction required |
| Scope | Unchanged (U) | Impact is within the same authorization boundary (the channel) |
| Confidentiality | Low (L) | Can read messages in a channel the user should no longer access |
| Integrity | Low (L) | Can post, edit, and delete messages in the channel |
| Availability | None (N) | No denial of service |
Attack Scenario
- User A and User B are members of a private group channel.
- The channel owner removes User B (or User B leaves). User B's membership is set to
is active=False, status='left'. - The channel disappears from User B's UI — but User B noted the channel ID while they were a member.
- User B calls the API directly:
GET /api/v1/channels/{channel id}/messages— reads all messages, including those posted after deactivationPOST /api/v1/channels/{channel id}/messages/post— posts new messagesPOST /api/v1/channels/{channel id}/messages/{id}/update— edits messagesDELETE /api/v1/channels/{channel id}/messages/{id}/delete— deletes messages
- All requests succeed because
is user channel memberreturnsTrue.
Impact
- Deactivated users can continue reading all new messages posted after their removal (confidentiality breach)
- Deactivated users can post, edit, and delete messages (integrity breach)
- The deactivation mechanism provides a false sense of security — channel owners believe removed users have lost access
Preconditions
- Channels feature must be enabled (disabled by default)
- Attacker must have a valid user account
- Attacker must have been a member of the channel at some point (and thus knows the channel ID)
Recommended Fix
Add
is active filtering to is user channel member:python
def is user channel member(self, channel id, user id, db=None):
membership = db.query(ChannelMember).filter(
ChannelMember.channel id == channel id,
ChannelMember.user id == user id,
ChannelMember.is active.is (True),
).first()
return membership is not NoneThis aligns it with the existing
get channel by id and user id method which already applies this filter correctly.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Webui