← Zurück zur CVE-Suche

CVE-2026-54022

Open WebUI

Beschreibung

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer normalizes all document IDs by replacing colons with underscores (document_id.replace(-:-, -_-)). An attacker can join a document room using note_<id> (underscore) instead of note:<id> (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim-s private note contents. This vulnerability is fixed in 0.8.11.

CVSS 5.3EPSS 0.32%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-06-23 18:18:07
Betroffene Versionen
<0.8.11
Typ
Kritische Software
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N