Junglewise Threat Intelligence

CVE-2026-45387: Open WebUI system prompt leakage via model API

CVE-2026-45387 · Severity: medium · CVSS 4.3 · Published 2026-05-15

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a self-hosted interface for interacting with AI models. A security flaw allowed users who were granted permission to use a specific AI model to also view its internal 'system prompt'—the hidden instructions that define how the AI behaves. This could lead to the exposure of proprietary instructions or sensitive configuration details that the model creator intended to keep confidential.

Technical details

An information disclosure vulnerability (CWE-200) exists in Open WebUI versions prior to 0.9.5. While the application correctly prevents unauthorized users from modifying models, the '/api/v1/models/model' endpoint fails to strip sensitive parameters when accessed by users with read-only permissions. An authenticated attacker with 'read' access to a model can retrieve the full 'params.system' object by directly querying the API with the model ID, even if the model is hidden from their standard workspace list. This results in system prompt leakage. The issue was resolved in version 0.9.5 by ensuring the API strips the 'params' dictionary for callers without write access.

Affected products

  • Open WebUI Open WebUI <= 0.9.4

Timeline

  • 2026-05-10: patched: Version 0.9.5 released
  • 2026-05-14: advisory: GitHub Advisory GHSA-h2cw-7qw9-56xr published

References

Related threats