Junglewise Threat Intelligence

CVE-2026-45395: Open WebUI authorization bypass in tool update endpoint

CVE-2026-45395 · Severity: high · CVSS 7.2 · Published 2026-05-15

Technologies: Open WebUI Open-Webui.

Executive brief

Open WebUI is an interface for interacting with large language models. A security flaw in the 'Tools' component—which allows users to extend the system with custom Python scripts—fails to properly check permissions when a tool is updated. This allows a user who has been granted basic editing access to a tool to inject and execute malicious code on the server, potentially leading to a full system takeover, data theft, or unauthorized access to internal networks.

Technical details

The vulnerability exists in the `update_tools_by_id` function within `backend/open_webui/routers/tools.py`. While the tool creation endpoint correctly enforces the `workspace.tools` permission, the update endpoint (`POST /api/v1/tools/id/{id}/update`) only verifies if the user is the owner or has a 'write' access grant. Because updating a tool triggers the `exec()` sink to load Python content, an attacker with 'write' access can replace the tool's content with malicious Python code. This results in Remote Code Execution (RCE) as the user running the application (often root in Docker environments), bypassing the intended security boundary where only trusted users should manage tools. The issue is fixed in version 0.9.5.

Affected products

  • Open WebUI Open WebUI < 0.9.5

Timeline

  • 2026-05-14: advisory: GitHub Advisory published
  • 2026-05-14: patched: Fixed in version 0.9.5

References