Executive brief
Open WebUI is a self-hosted interface for running artificial intelligence models offline. A security flaw allows regular users to bypass administrative restrictions and send requests to restricted or disabled AI backends. While this does not expose private user data, it allows unauthorized users to consume expensive computing resources or access high-privilege AI models they should not be able to reach.
Technical details
An incorrect authorization vulnerability exists in Open WebUI's Ollama proxy routes. The 'get_ollama_url' function in 'backend/open_webui/routers/ollama.py' fails to validate the 'url_idx' path parameter against the requested model's authorized backend list when the index is explicitly provided by the caller. An authenticated attacker can provide an arbitrary index to route requests to any configured 'OLLAMA_BASE_URLS', including internal, high-privilege, or admin-disabled backends. The requests are executed using the server's configured API keys for those backends. The issue is resolved in version 0.9.6 by implementing 'validate_ollama_backend_idx' to enforce backend mapping checks.
Affected products
- open-webui open-webui < 0.9.6
Timeline
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: NVD publication date
- 2026-06-23: patched: Fix confirmed in version 0.9.6