Junglewise Threat Intelligence

CVE-2026-59213: Open WebUI information disclosure via static cache key in get_all_models

CVE-2026-59213 · Severity: low · CVSS 3.5 · Published 2026-07-09

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI is a user interface for interacting with AI models. A flaw in how the system caches model lists allows one user to potentially see the names and availability of AI models that should only be visible to a different user. This could lead to the unauthorized disclosure of sensitive model names or the existence of restricted internal AI tools.

Technical details

A vulnerability exists in the get_all_models handlers within routers/openai.py and routers/ollama.py due to the misuse of the @cached decorator from the aiocache library. The implementation used a static 'key=' parameter instead of a dynamic 'key_builder=', causing all users to share a single cache entry for permission-filtered model lists. An authenticated attacker can exploit this by requesting their model list immediately after another user, potentially receiving the victim's filtered list during the 1-second TTL window. This results in a cross-user authorization boundary bypass (CWE-524). The issue is resolved in version 0.10.0 by correctly implementing key_builder.

Affected products

  • Open WebUI open-webui >= 0.6.27, < 0.10.0

Timeline

  • 2026-07-02: disclosed
  • 2026-07-09: advisory: NVD publication
  • 2026-07-24: patched: GitHub Advisory published/updated

References

Related threats