Junglewise Threat Intelligence

CVE-2026-54009: Open WebUI authorization bypass in chat completions endpoint

CVE-2026-54009 · Severity: medium · CVSS 6.5 · Published 2026-06-23

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a self-hosted platform for running artificial intelligence models. A security flaw allows logged-in users to access files uploaded by other users by tricking the system into processing those files as images. This could lead to the unauthorized disclosure of sensitive documents or private images stored on the platform.

Technical details

An authorization bypass (CWE-639) exists in the 'POST /api/chat/completions' endpoint of Open WebUI. The 'convert_url_images_to_base64' function in 'middleware.py' fails to validate file ownership when an 'image_url.url' value is provided as a file ID rather than a standard URL. An authenticated attacker can provide a known file ID belonging to another user; the server then retrieves the file from disk, base64-encodes it, and includes it in the LLM request. By prompting the LLM to describe or transcribe the "image," the attacker can extract the contents of the private file. This issue is resolved in version 0.9.6 by implementing proper ownership checks.

Affected products

  • open-webui Open WebUI < 0.9.6

Timeline

  • 2026-06-11: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: NVD publication date

References

Related threats