<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T21:46:53.049765+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07224</id>
    <title>bdu:2026-07224</title>
    <updated>2026-10-10T21:46:53.147048+00:00</updated>
    <content>bdu:2026-07224</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-319249</id>
    <title>EUVD-2026-319249</title>
    <updated>2026-10-10T21:46:53.147116+00:00</updated>
    <content>EUVD-2026-319249</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-319249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45397</id>
    <title>fkie_cve-2026-45397</title>
    <updated>2026-10-10T21:46:53.147131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header, cookie, or API key is required. Every adjacent endpoint on the same router (/embedding, /config) is correctly guarded by get_admin_user making this a targeted omission. This vulnerability is fixed in 0.9.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-65pg-qhhw-mxwg</id>
    <title>GHSA-65pg-qhhw-mxwg — Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure</title>
    <updated>2026-10-10T21:46:53.147166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>**Vulnerability Type:** Information Disclosure / Missing Authentication  
**Severity:** Medium  
**Component:** `backend/open_webui/routers/retrieval.py` — `get_status()` (`GET /`)  
**Affected Endpoint:** `GET /api/v1/retrieval/`  
**Affected Version:** Open WebUI `main` branch — confirmed unpatched through **v0.9.2**  
**Authentication Required:** None — internet-facing with zero credentials  
**CVSSv3.1 Score:** 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)</p>
<p>---</p>
<p>## Summary</p>
<p>`GET /api/v1/retrieval/` returns live RAG pipeline configuration to any unauthenticated HTTP client. No `Authorization` header, cookie, or API key is required. Every adjacent endpoint on the same router (`/embedding`, `/config`) is correctly guarded by `get_admin_user` making this a targeted omission.</p>
<p>---</p>
<p>## Root Cause</p>
<p>`backend/open_webui/routers/retrieval.py:262`</p>
<p>```python
@router.get('/')
async def get_status(request: Request):   # ← no Depends(get_verified_user)
    return {
        'status': True,
        'CHUNK_SIZE': request.app.state.config.CHUNK_SIZE,
        'CHUNK_OVERLAP': request.app.state.config.CHUNK_OVERLAP,
        'RAG_TEMPLATE': request.app.state.config.RAG_TEMPLATE,
        'RAG_EMBEDDING_ENGINE': request.app.state.config.RAG_EMBEDDING_ENGINE,
        'RAG_EMBEDDING_MODEL': request.app.state.config.RAG_EMBEDDING_MODEL,
        'RAG_RERANKING_MODEL': request.app.state.config.RAG_RERANKING_MODEL,
        'RAG_EMBEDDING_BATCH_SIZE': request.app.state.config.RAG_EMBEDDING_BATCH_SIZE,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-65pg-qhhw-mxwg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2706</id>
    <title>PYSEC-2026-2706 — Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure</title>
    <updated>2026-10-10T21:46:53.147265+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>**Vulnerability Type:** Information Disclosure / Missing Authentication  
**Severity:** Medium  
**Component:** `backend/open_webui/routers/retrieval.py` — `get_status()` (`GET /`)  
**Affected Endpoint:** `GET /api/v1/retrieval/`  
**Affected Version:** Open WebUI `main` branch — confirmed unpatched through **v0.9.2**  
**Authentication Required:** None — internet-facing with zero credentials  
**CVSSv3.1 Score:** 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)</p>
<p>---</p>
<p>## Summary</p>
<p>`GET /api/v1/retrieval/` returns live RAG pipeline configuration to any unauthenticated HTTP client. No `Authorization` header, cookie, or API key is required. Every adjacent endpoint on the same router (`/embedding`, `/config`) is correctly guarded by `get_admin_user` making this a targeted omission.</p>
<p>---</p>
<p>## Root Cause</p>
<p>`backend/open_webui/routers/retrieval.py:262`</p>
<p>```python
@router.get('/')
async def get_status(request: Request):   # ← no Depends(get_verified_user)
    return {
        'status': True,
        'CHUNK_SIZE': request.app.state.config.CHUNK_SIZE,
        'CHUNK_OVERLAP': request.app.state.config.CHUNK_OVERLAP,
        'RAG_TEMPLATE': request.app.state.config.RAG_TEMPLATE,
        'RAG_EMBEDDING_ENGINE': request.app.state.config.RAG_EMBEDDING_ENGINE,
        'RAG_EMBEDDING_MODEL': request.app.state.config.RAG_EMBEDDING_MODEL,
        'RAG_RERANKING_MODEL': request.app.state.config.RAG_RERANKING_MODEL,
        'RAG_EMBEDDING_BATCH_SIZE': request.app.state.config.RAG_EMBEDDING_BATCH_SIZE,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2706"/>
  </entry>
</feed>
