Executive brief
Open WebUI, a user interface for interacting with large language models, contains a security flaw in its channel messaging system. An authenticated user with basic read access to a channel can modify or delete messages posted by any other user in that same channel. This allows malicious actors to tamper with conversation history, delete important information, or impersonate others by changing the content of their messages.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `update_message_by_id` and `delete_message_by_id` endpoints within `backend/open_webui/routers/channels.py`. While the backend validates that a user has 'read' access to a channel, it fails to verify message ownership or 'write' permissions before performing update or delete operations. An authenticated attacker can bypass frontend restrictions by sending direct API requests with a victim's `message_id` to modify or remove content. This vulnerability is patched in version 0.6.19.
Affected products
- Open WebUI open-webui <= 0.6.18
Timeline
- 2026-05-05: disclosed: Initial disclosure by geckosecurity
- 2026-05-11: advisory: GitHub Advisory published
- 2026-05-15: patched: NVD publication and patch availability confirmed
References
- https://api.github.com/users/geckosecurity
- https://github.com/geckosecurity
- https://api.github.com/users/geckosecurity/gists%7B/gist_id%7D
- https://api.github.com/users/geckosecurity/repos
- https://avatars.githubusercontent.com/u/188164982?v=4
- https://api.github.com/users/geckosecurity/events%7B/privacy%7D