Executive brief
Open WebUI is a user interface for interacting with AI models. A flaw in how the system caches model lists allows one user to potentially see the names and availability of AI models that should only be visible to a different user. This could lead to the unauthorized disclosure of sensitive model names or the existence of restricted internal AI tools.
Technical details
A vulnerability exists in the get_all_models handlers within routers/openai.py and routers/ollama.py due to the misuse of the @cached decorator from the aiocache library. The implementation used a static 'key=' parameter instead of a dynamic 'key_builder=', causing all users to share a single cache entry for permission-filtered model lists. An authenticated attacker can exploit this by requesting their model list immediately after another user, potentially receiving the victim's filtered list during the 1-second TTL window. This results in a cross-user authorization boundary bypass (CWE-524). The issue is resolved in version 0.10.0 by correctly implementing key_builder.
Affected products
- Open WebUI open-webui >= 0.6.27, < 0.10.0
Timeline
- 2026-07-02: disclosed
- 2026-07-09: advisory: NVD publication
- 2026-07-24: patched: GitHub Advisory published/updated