Executive brief
Open WebUI, a popular interface for interacting with Large Language Models (LLMs), contains a vulnerability where non-administrative users can view sensitive system prompts. These prompts often contain proprietary instructions, safety guidelines, and operational constraints set by administrators. An attacker with a standard user account could use this information to understand the system's internal logic or find ways to bypass AI safety restrictions.
Technical details
An information disclosure vulnerability (CWE-200) exists in Open WebUI versions up to 0.8.8. The application's API endpoint `/api/models` returns the full configuration of available models, including the 'system prompt' field, to any authenticated user regardless of their privilege level. This allows a regular user to retrieve administrative instructions and internal model logic. An attacker can exploit this by capturing the JSON response from the models API. The vulnerability is categorized under OWASP LLM07:2025 (System Prompt Leakage). A fix is available in version 0.8.9.
Affected products
- Open WebUI Open WebUI <= 0.8.8
Timeline
- 2026-05-09: disclosed: Vulnerability reported to vendor
- 2026-05-14: advisory: GitHub Advisory published
- 2026-05-14: patched: Version 0.8.9 released