MEDIUM 6.5 GitHub
CVE-2026-70491
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
## Summary
A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared publicly. Source is meant to be a writer-only tier: the list response schema deliberately omits it and source export sits behind its own permission. The read endpoints delivered it anyway.
## Preconditions
- Authentication enabled (`WEBUI_AUTH=true`, d
Affected Products
- pip/open-webui <= 0.10.2
References
- https://github.com/advisories/GHSA-3r7g-q6cg-q2vx
- https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx
- https://github.com/open-webui/open-webui/pull/27005
- https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-04 via GitHub. Affected: pip/open-webui <= 0.10.2.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.