CVE-2026-59714
🟡 Monitoruj
Niezabezpieczona funkcjonalność w Open WebUI pozwala na modyfikację wiadomości przez uwierzytelnionych użytkowników.
CVSS
7.1
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This issue is fixed in version 0.10.0.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-08-13 20:17:23 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-18 20:09:01 UTC |
Referencje
- https://github.com/open-webui/open-webui/commit/ac3449cac91e62b08a7c28e54fcd044d14dea791 ([email protected])
- https://github.com/open-webui/open-webui/pull/26385 ([email protected])
- https://github.com/open-webui/open-webui/releases/tag/v0.10.0 ([email protected])
- https://github.com/open-webui/open-webui/security/advisories/GHSA-x2ff-v5v8-m75m ([email protected])