← Voltar à pesquisa de CVEs

CVE-2026-70484

Descrição

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.image_generation permission that the direct image routes and native function-calling path enforce. An authenticated user whose image-generation permission had been revoked could still consume the operator-s configured image provider through chat completions, spending API credits and provider quota and writing generated files to operator storage, without exposing provider credentials or other users- data. This issue is fixed in 0.11.0.

CVSS 4.3EPSS 0.267%Risco 0.44
Ver fonte
Publicação
2026-08-04 20:16:55
Última alteração
2026-08-05 16:17:02
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L