PT-2026-39277 · Unknown · Open-Webui
Published
2026-05-08
·
Updated
2026-05-16
·
CVE-2026-44560
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open WebUI versions prior to 0.9.0
Description
The
get sources from items() function resolves file and knowledge base references into vector search queries during chat completion. Certain code paths perform vector store queries without authorization checks, allowing users to extract content from files and knowledge bases they are not permitted to access. Specifically, the issue occurs when using type: "file" (non-full-context), type: "text" with collection name, or bare collection name/collection names paths. These paths pass user-supplied collection names directly to query collection(), which queries the vector store without verifying permissions. This can be exploited via the '/api/chat/completions' endpoint by providing a known file ID or knowledge base UUID in the request.Recommendations
Update to version 0.9.0.
As a temporary workaround, restrict access to the '/api/chat/completions' endpoint to trusted users only.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui