← Back to CVE search

CVE-2026-54022

Open WebUI

Description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer normalizes all document IDs by replacing colons with underscores (document_id.replace(-:-, -_-)). An attacker can join a document room using note_<id> (underscore) instead of note:<id> (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim-s private note contents. This vulnerability is fixed in 0.8.11.

CVSS 5.3EPSS 0.32%Risk 0.55
View source
Published
2026-06-23 18:18:07
Affected versions
<0.8.11
Type
Critical software
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N