Executive brief
An authenticated user can overwrite messages in any chat channel, including private and direct messages they do not have permission to access. This allows an attacker to change the content of existing messages while making it appear as though the original author wrote them, potentially leading to misinformation or impersonation within the platform.
Technical details
A missing authorization check in the chat completion API allows authenticated users to overwrite messages across different channels. When a request uses a 'channel:'-prefixed chat_id, the application skips ownership verification and passes user-supplied message IDs directly to a database update function. This function, `_make_channel_emitter`, performs updates based on the primary key without verifying if the message belongs to the specified channel or if the user has access to it. This affects both single-model requests and multimodel requests using the `message_ids` map. The vulnerability is patched in version 0.10.0 by implementing per-entry validation and a fail-closed emitter that verifies channel ownership before writing.
Affected products
- Open WebUI open-webui >= 0.9.5, < 0.10.0
Timeline
- 2026-07-02: disclosed: Initial disclosure on GitHub
- 2026-07-24: advisory: GitHub Advisory published
- 2026-07-24: patched: Fix confirmed in version 0.10.0