<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:07:43.070599+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335439</id>
    <title>EUVD-2026-335439</title>
    <updated>2026-10-10T18:07:43.175153+00:00</updated>
    <content>EUVD-2026-335439</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59212</id>
    <title>fkie_cve-2026-59212</title>
    <updated>2026-10-10T18:07:43.175202+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file write and delete routes later trusted object-derived access through writable model meta.knowledge entries, allowing a user with read-only knowledge file access to upgrade to file write or delete operations. This issue is fixed in version 0.10.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59212"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2xwm-4h2q-ggfx</id>
    <title>GHSA-2xwm-4h2q-ggfx — Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete</title>
    <updated>2026-10-10T18:07:43.175270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>## Summary</p>
<p>Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.</p>
<p>This is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_verify_knowledge_file_access()`, but the validator only checks `has_access_to_file(file_id, "read", user)`. The file write/delete routes later trust `has_access_to_file(file_id, "write", user)`, and that function grants access through any writable model whose `meta.knowledge` contains the file ID.</p>
<p>The PoV includes a negative control showing the current validator rejects an inaccessible arbitrary file ID. The residual issue is narrower: a file ID that is readable only through a KB read grant is accepted into direct model file metadata, then the same model metadata satisfies later file write/delete checks.</p>
<p>## Technical Details</p>
<p>`backend/open_webui/routers/models.py::_verify_knowledge_file_access()` accepts model `meta.knowledge` file entries when the caller can read the file:</p>
<p>```python
if not await has_access_to_file(file_id, 'read', user, db=db):
    raise HTTPException(...)
```</p>
<p>`backend/open_webui/utils/access_control/files.py::has_access_to_file()` then uses attacker-writable model metadata as a source for any requested access type:</p>
<p>```python
for model in await Models.get_models_by_user_id(user.id, permission=access_type, db=db):
    knowledge_items = getattr(model.meta, 'kn…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2xwm-4h2q-ggfx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3588</id>
    <title>PYSEC-2026-3588 — Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete</title>
    <updated>2026-10-10T18:07:43.175342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>## Summary</p>
<p>Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.</p>
<p>This is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_verify_knowledge_file_access()`, but the validator only checks `has_access_to_file(file_id, "read", user)`. The file write/delete routes later trust `has_access_to_file(file_id, "write", user)`, and that function grants access through any writable model whose `meta.knowledge` contains the file ID.</p>
<p>The PoV includes a negative control showing the current validator rejects an inaccessible arbitrary file ID. The residual issue is narrower: a file ID that is readable only through a KB read grant is accepted into direct model file metadata, then the same model metadata satisfies later file write/delete checks.</p>
<p>## Technical Details</p>
<p>`backend/open_webui/routers/models.py::_verify_knowledge_file_access()` accepts model `meta.knowledge` file entries when the caller can read the file:</p>
<p>```python
if not await has_access_to_file(file_id, 'read', user, db=db):
    raise HTTPException(...)
```</p>
<p>`backend/open_webui/utils/access_control/files.py::has_access_to_file()` then uses attacker-writable model metadata as a source for any requested access type:</p>
<p>```python
for model in await Models.get_models_by_user_id(user.id, permission=access_type, db=db):
    knowledge_items = getattr(model.meta, 'kn…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3588"/>
  </entry>
</feed>
