Junglewise Threat Intelligence

CVE-2026-54015: Open WebUI IDOR in prompt history endpoints

CVE-2026-54015 · Severity: medium · CVSS 6.4 · Published 2026-06-17

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a self-hosted platform for running artificial intelligence models offline. A security flaw in the prompt management system allows an authenticated user to view or delete the private prompt history of other users. This could lead to the exposure of sensitive instructions, private data, or internal variables stored within another user's AI prompt versions.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Open WebUI's prompt version-history endpoints prior to version 0.9.6. While the application validates that a user has access to the `prompt_id` provided in the URL, it fails to verify that the requested `history_id` or `version_id` actually belongs to that authorized prompt. An authenticated attacker can exploit this by supplying a victim's history UUID to the `/history/diff`, `/update/version`, or DELETE endpoints. This allows the attacker to retrieve full snapshots of private prompts (including content and internal instructions) or delete history entries. The vulnerability is rooted in the `compute_diff`, `update_prompt_version`, and `delete_history_entry` functions which fetch records globally by ID without a secondary ownership check. This is fixed in version 0.9.6.

Affected products

  • open-webui open-webui < 0.9.6

Timeline

  • 2026-06-11: advisory: GitHub advisory published by maintainers
  • 2026-06-23: disclosed: NVD publication date
  • 2026-06-23: patched: Fix confirmed in version 0.9.6

References

Related threats