Executive brief
Open WebUI is a self-hosted interface for interacting with AI models. A security flaw allowed users who were granted permission to use a specific AI model to also view its internal 'system prompt'—the hidden instructions that define how the AI behaves. This could lead to the exposure of proprietary instructions or sensitive configuration details that the model creator intended to keep confidential.
Technical details
An information disclosure vulnerability (CWE-200) exists in Open WebUI versions prior to 0.9.5. While the application correctly prevents unauthorized users from modifying models, the '/api/v1/models/model' endpoint fails to strip sensitive parameters when accessed by users with read-only permissions. An authenticated attacker with 'read' access to a model can retrieve the full 'params.system' object by directly querying the API with the model ID, even if the model is hidden from their standard workspace list. This results in system prompt leakage. The issue was resolved in version 0.9.5 by ensuring the API strips the 'params' dictionary for callers without write access.
Affected products
- Open WebUI Open WebUI <= 0.9.4
Timeline
- 2026-05-10: patched: Version 0.9.5 released
- 2026-05-14: advisory: GitHub Advisory GHSA-h2cw-7qw9-56xr published