MEDIUM 5.3 GitHub
CVE-2026-70487
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
## Summary
Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file id could therefore have the builtin knowledge tools return that file's indexed content back to them.
## Preconditions
Authenticated user of any role, no admin rights needed. The request must carry a s
Affected Products
- pip/open-webui >= 0.8.8, <= 0.10.2
References
- https://github.com/advisories/GHSA-6xhv-rxhv-pwm4
- https://github.com/open-webui/open-webui/security/advisories/GHSA-6xhv-rxhv-pwm4
- https://github.com/open-webui/open-webui/commit/305880f2e2aeb2dda2f4b2a18a20bdcd558f7134
- https://github.com/open-webui/open-webui/releases/tag/v0.11.0
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-04 via GitHub. Affected: pip/open-webui >= 0.8.8, <= 0.10.2.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.