Executive brief
Open WebUI, a popular interface for interacting with large language models, contains a flaw where user sessions are not properly terminated for real-time features. When a user signs out or an administrator revokes access, an attacker with a stolen session token can still maintain access to real-time chat messages, collaborative notes, and terminal sessions. This could lead to unauthorized monitoring of private communications or unauthorized access to connected server terminals.
Technical details
Open WebUI versions 0.9.0 through 0.9.x fail to enforce JWT revocation checks on real-time communication paths, including Socket.IO (connect, user-join, join-channels, join-note) and terminal websocket endpoints. While standard HTTP REST endpoints correctly consult Redis to verify if a token's JTI or a user's 'revoked_at' timestamp has been invalidated, the real-time handlers only perform standard signature and expiration validation via 'decode_token()'. An attacker with a previously valid but now revoked JWT can establish new websocket connections to intercept real-time messages or access terminal servers if configured. This vulnerability is only present in deployments using Redis for session management. The issue is resolved in version 0.10.0 by centralizing revocation logic.
Affected products
- Open WebUI Open WebUI >= 0.9.0, < 0.10.0
Timeline
- 2026-07-02: disclosed: Advisory published on GitHub
- 2026-07-09: advisory: NVD publication date
- 2026-07-24: patched: Final advisory update and patch confirmation