<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T06:59:50.021183+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07144</id>
    <title>bdu:2026-07144</title>
    <updated>2026-10-05T06:59:50.105173+00:00</updated>
    <content>bdu:2026-07144</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319336</id>
    <title>EUVD-2026-319336</title>
    <updated>2026-10-05T06:59:50.105212+00:00</updated>
    <content>EUVD-2026-319336</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45351</id>
    <title>fkie_cve-2026-45351</title>
    <updated>2026-10-05T06:59:50.105228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application. This vulnerability is fixed in 0.8.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jh9g-8jqw-m2qx</id>
    <title>GHSA-jh9g-8jqw-m2qx — Open WebUI Exposes System Prompt to Regular User [Non-Admin]</title>
    <updated>2026-10-05T06:59:50.105260+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._</p>
<p>### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_</p>
<p>### Affected System
_Open WebUI v0.6.40 "main" branch_</p>
<p>### Vulnerability Details and Advisory from OWASP
LLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/</p>
<p>### PoC
_1. Regular User [Non-Admin] login on Open WebUI application._
_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._
_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._
&lt;img width="940" height="352" alt="system prompt leak" src="https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560" /&gt;</p>
<p>### Web Request
GET /api/models? HTTP/1.1
Host: localhost:8080
sec-ch-ua-platform: "Linux"
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Accept-Language: en-US,en;q=0.9
sec-ch-ua: "Chromium";v="141", "Not?A_Brand";…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jh9g-8jqw-m2qx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2741</id>
    <title>PYSEC-2026-2741 — Open WebUI Exposes System Prompt to Regular User [Non-Admin]</title>
    <updated>2026-10-05T06:59:50.105312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._</p>
<p>### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_</p>
<p>### Affected System
_Open WebUI v0.6.40 "main" branch_</p>
<p>### Vulnerability Details and Advisory from OWASP
LLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/</p>
<p>### PoC
_1. Regular User [Non-Admin] login on Open WebUI application._
_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._
_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._
&lt;img width="940" height="352" alt="system prompt leak" src="https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560" /&gt;</p>
<p>### Web Request
GET /api/models? HTTP/1.1
Host: localhost:8080
sec-ch-ua-platform: "Linux"
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Accept-Language: en-US,en;q=0.9
sec-ch-ua: "Chromium";v="141", "Not?A_Brand";…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1542</id>
    <title>WID-SEC-W-2026-1542 — Google Chrome und Microsoft Edge: Mehrere Schwachstellen</title>
    <updated>2026-10-05T06:59:50.105355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Google Chrome und Microsoft Edge ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1542"/>
  </entry>
</feed>
