Executive brief
Open WebUI is a user interface for interacting with large language models that includes a note-sharing feature. A flaw in the system allows users who have been granted 'read-only' access to a note to change its 'pinned' status, an action that should be restricted to owners or editors. While this does not allow unauthorized users to change the content of a note, it allows them to modify the note's organization and visibility for other users.
Technical details
An incorrect authorization check exists in the `POST /api/v1/notes/{id}/pin` endpoint within `backend/open_webui/routers/notes.py`. The endpoint performs a state-modifying operation (toggling the `is_pinned` boolean) but validates the user's access against the 'read' permission instead of the 'write' permission. An attacker with authenticated network access and explicit read-only sharing permissions for a note can exploit this to pin or unpin the note, affecting its display for the owner and other shared users. The vulnerability is limited to the `is_pinned` field and does not permit modification of note content or access control lists. The issue is resolved in version 0.9.3.
Affected products
- Open WebUI open-webui <= 0.9.2
Timeline
- 2026-05-09: disclosed: Initial report by qi-scape
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-14: patched: Fixed in version 0.9.3