← Zurück zur CVE-Suche

CVE-2026-70487

Beschreibung

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller-s read access. Any authenticated user who knew another user-s file id could have the builtin knowledge tools return indexed chunks from that file, causing a read-only cross-user confidentiality loss while leaving knowledge-base permissions and saved workspace model validation unaffected. This issue is fixed in 0.11.0.

CVSS 5.3EPSS 0.25%Risiko 0.54
Quelle öffnen
Veröffentlicht
2026-08-04 21:16:37
Zuletzt geändert
2026-08-05 16:17:02
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N