<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:58:05.119852+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-54022</id>
    <title>CVE-2026-54022 — Open WebUI: Any authenticated user can read other users' private notes via Socket.IO</title>
    <updated>2026-10-05T03:58:05.135982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> open-webui</p>
<p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer normalizes all document IDs by replacing colons with underscores (document_id.replace(":", "_")). An attacker can join a document room using note_&lt;id&gt; (underscore) instead of note:&lt;id&gt; (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim's private note contents. This vulnerability is fixed in 0.8.11.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-54022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8788-j68r-3cgh</id>
    <title>GHSA-8788-j68r-3cgh — Open WebUI: Any authenticated user can read other users' private notes via Socket.IO</title>
    <updated>2026-10-05T03:58:05.136049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>### Summary</p>
<p>The `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(":", "_")`). An attacker can join a document room using `note_&lt;id&gt;` (underscore) instead of `note:&lt;id&gt;` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim's private note contents.</p>
<p>### Details</p>
<p>The `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:</p>
<p>```python
@sio.on("ydoc:document:join")
async def ydoc_document_join(sid, data):
    document_id = data["document_id"]</p>
<p>if document_id.startswith("note:"):
        note_id = document_id.split(":")[1]
        note = Notes.get_note_by_id(note_id)
        # ... ownership and AccessGrants check ...
        # Returns early if user doesn't have access</p>
<p># If document_id does NOT start with "note:", execution continues
    # with no authorization check at all</p>
<p>await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)
    await sio.enter_room(sid, f"doc_{document_id}")</p>
<p>ydoc = Y.Doc()
    updates = await YDOC_MANAGER.get_updates(document_id)
    for update in updates:
        ydoc.apply_update(bytes(update))</p>
<p>state_update = ydoc.get_update()
    await sio…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8788-j68r-3cgh"/>
  </entry>
</feed>
