Executive brief
Open WebUI is an interface for interacting with large language models. A vulnerability in its terminal proxy allows an authenticated user to impersonate other users. This could allow an attacker to hijack another person's active terminal session, potentially leading to unauthorized access to data or the ability to execute commands in another user's environment.
Technical details
The terminal proxy in `backend/open_webui/routers/terminals.py` fails to cryptographically bind user identities to sessions when forwarding requests to upstream backends. In the HTTP path, the `X-User-Id` header is sent unsigned, allowing spoofing if the upstream is reachable via SSRF or other means. In the WebSocket path (`ws_terminal`), the `session_id` path parameter is interpolated into the upstream URL without validation or encoding. An attacker can use query injection (smuggling `?` or `&` characters) to override the `user_id` parameter. This allows a low-privileged user to attach to another user's live pseudo-terminal (PTY) if the session ID is known. The issue is fixed in version 0.10.0.
Affected products
- Open WebUI Open WebUI < 0.10.0
Timeline
- 2026-07-02: disclosed: Initial report by smoke-wolf
- 2026-07-09: advisory: NVD publication
- 2026-07-24: patched: Version 0.10.0 released