Junglewise Threat Intelligence

CVE-2026-45351: Open WebUI information disclosure in system prompts

CVE-2026-45351 · Severity: medium · CVSS 6.5 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a popular interface for interacting with Large Language Models (LLMs), contains a vulnerability where non-administrative users can view sensitive system prompts. These prompts often contain proprietary instructions, safety guidelines, and operational constraints set by administrators. An attacker with a standard user account could use this information to understand the system's internal logic or find ways to bypass AI safety restrictions.

Technical details

An information disclosure vulnerability (CWE-200) exists in Open WebUI versions up to 0.8.8. The application's API endpoint `/api/models` returns the full configuration of available models, including the 'system prompt' field, to any authenticated user regardless of their privilege level. This allows a regular user to retrieve administrative instructions and internal model logic. An attacker can exploit this by capturing the JSON response from the models API. The vulnerability is categorized under OWASP LLM07:2025 (System Prompt Leakage). A fix is available in version 0.8.9.

Affected products

  • Open WebUI Open WebUI <= 0.8.8

Timeline

  • 2026-05-09: disclosed: Vulnerability reported to vendor
  • 2026-05-14: advisory: GitHub Advisory published
  • 2026-05-14: patched: Version 0.8.9 released

References

Related threats