Executive brief
Open WebUI is a user interface for interacting with large language models. A security flaw allows an authenticated user to read private messages from channels they are not members of by exploiting how the system handles message threads. This could lead to the unauthorized disclosure of sensitive conversations and user metadata if an attacker knows or can guess a message ID.
Technical details
An authorization bypass (CWE-639) exists in Open WebUI's channel message handling. The 'get_messages_by_parent_id' function in 'backend/open_webui/models/messages.py' retrieves a thread's parent message by ID without verifying that the message belongs to the channel the user is authorized to access. An attacker can exploit this by calling the thread retrieval endpoint for a channel they have access to while providing a 'message_id' belonging to a private channel. This results in the API returning the content, channel ID, and author of the private message. The vulnerability is patched in version 0.10.0 by enforcing channel-binding checks on both read and write paths.
Affected products
- Open WebUI Open WebUI < 0.10.0
Timeline
- 2026-07-02: disclosed: Initial disclosure on GitHub
- 2026-07-09: advisory: NVD publication date
- 2026-07-24: advisory: GitHub Advisory reviewed and updated
- 2026-07-24: patched: Version 0.10.0 released