Junglewise Threat Intelligence

CVE-2026-59222: Open WebUI information disclosure in channel members API

CVE-2026-59222 · Severity: medium · CVSS 4 · Published 2026-07-09

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

Open WebUI, a popular interface for interacting with large language models, contains a vulnerability where sensitive user information is unintentionally shared. A standard user can access private configuration details of other participants in a chat channel, including administrators. This could allow an attacker to steal secret credentials, such as API keys and webhook URLs, potentially leading to unauthorized access to connected services.

Technical details

An information disclosure vulnerability exists in the GET `/api/v1/channels/{id}/members` endpoint of Open WebUI. The root cause is the use of `UserModelResponse(**user.model_dump())`, which serializes the entire user model including the `settings` object and `settings.ui` configuration. An authenticated attacker with low privileges can join a channel (such as a Direct Message) with an administrator and retrieve the admin's sensitive configuration data, including `toolServers` bearer tokens and webhook URLs. This data is normally restricted and not available through standard user info APIs. The issue is fixed in version 0.10.0.

Affected products

  • Open WebUI open-webui >= 0.7.0, < 0.10.0

Timeline

  • 2026-07-02: disclosed: Initial disclosure by reporter
  • 2026-07-09: advisory: NVD publication date
  • 2026-07-24: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats