<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 03:10:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329811</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329811</link>
      <description>EUVD-2026-329811</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329811</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54022</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54022</link>
      <description>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer normalizes all document IDs by replacing colons with underscores (document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)). An attacker can join a document room using note_&amp;lt;id&amp;gt; (underscore) instead of note:&amp;lt;id&amp;gt; (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents. This vulnerability is fixed in 0.8.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership only when the document_id starts with note: (colon). However, the YdocManager storage layer normalizes all document IDs by replacing colons with underscores (document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)). An attacker can join a document room using note_&amp;lt;id&amp;gt; (underscore) instead of note:&amp;lt;id&amp;gt; (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents. This vulnerability is fixed in 0.8.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54022</guid>
    </item>
    <item>
      <title>GHSA-8788-j68r-3cgh — Open WebUI: Any authenticated user can read other users' private notes via Socket.IO</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8788-j68r-3cgh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)`). An attacker can join a document room using `note_&amp;lt;id&amp;gt;` (underscore) instead of `note:&amp;lt;id&amp;gt;` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:&lt;/p&gt;
&lt;p&gt;```python
@sio.on(&amp;#34;ydoc:document:join&amp;#34;)
async def ydoc_document_join(sid, data):
    document_id = data[&amp;#34;document_id&amp;#34;]&lt;/p&gt;
&lt;p&gt;if document_id.startswith(&amp;#34;note:&amp;#34;):
        note_id = document_id.split(&amp;#34;:&amp;#34;)[1]
        note = Notes.get_note_by_id(note_id)
        # ... ownership and AccessGrants check ...
        # Returns early if user doesn&amp;#39;t have access&lt;/p&gt;
&lt;p&gt;# If document_id does NOT start with &amp;#34;note:&amp;#34;, execution continues
    # with no authorization check at all&lt;/p&gt;
&lt;p&gt;await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)
    await sio.enter_room(sid, f&amp;#34;doc_{document_id}&amp;#34;)&lt;/p&gt;
&lt;p&gt;ydoc = Y.Doc()
    updates = await YDOC_MANAGER.get_updates(document_id)
    for update in updates:
        ydoc.apply_update(bytes(update))&lt;/p&gt;
&lt;p&gt;state_update = ydoc.get_update()
    await sio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)`). An attacker can join a document room using `note_&amp;lt;id&amp;gt;` (underscore) instead of `note:&amp;lt;id&amp;gt;` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:&lt;/p&gt;
&lt;p&gt;```python
@sio.on(&amp;#34;ydoc:document:join&amp;#34;)
async def ydoc_document_join(sid, data):
    document_id = data[&amp;#34;document_id&amp;#34;]&lt;/p&gt;
&lt;p&gt;if document_id.startswith(&amp;#34;note:&amp;#34;):
        note_id = document_id.split(&amp;#34;:&amp;#34;)[1]
        note = Notes.get_note_by_id(note_id)
        # ... ownership and AccessGrants check ...
        # Returns early if user doesn&amp;#39;t have access&lt;/p&gt;
&lt;p&gt;# If document_id does NOT start with &amp;#34;note:&amp;#34;, execution continues
    # with no authorization check at all&lt;/p&gt;
&lt;p&gt;await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)
    await sio.enter_room(sid, f&amp;#34;doc_{document_id}&amp;#34;)&lt;/p&gt;
&lt;p&gt;ydoc = Y.Doc()
    updates = await YDOC_MANAGER.get_updates(document_id)
    for update in updates:
        ydoc.apply_update(bytes(update))&lt;/p&gt;
&lt;p&gt;state_update = ydoc.get_update()
    await sio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8788-j68r-3cgh</guid>
    </item>
    <item>
      <title>PYSEC-2026-2712 — Open WebUI: Any authenticated user can read other users' private notes via Socket.IO</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2712</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)`). An attacker can join a document room using `note_&amp;lt;id&amp;gt;` (underscore) instead of `note:&amp;lt;id&amp;gt;` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:&lt;/p&gt;
&lt;p&gt;```python
@sio.on(&amp;#34;ydoc:document:join&amp;#34;)
async def ydoc_document_join(sid, data):
    document_id = data[&amp;#34;document_id&amp;#34;]&lt;/p&gt;
&lt;p&gt;if document_id.startswith(&amp;#34;note:&amp;#34;):
        note_id = document_id.split(&amp;#34;:&amp;#34;)[1]
        note = Notes.get_note_by_id(note_id)
        # ... ownership and AccessGrants check ...
        # Returns early if user doesn&amp;#39;t have access&lt;/p&gt;
&lt;p&gt;# If document_id does NOT start with &amp;#34;note:&amp;#34;, execution continues
    # with no authorization check at all&lt;/p&gt;
&lt;p&gt;await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)
    await sio.enter_room(sid, f&amp;#34;doc_{document_id}&amp;#34;)&lt;/p&gt;
&lt;p&gt;ydoc = Y.Doc()
    updates = await YDOC_MANAGER.get_updates(document_id)
    for update in updates:
        ydoc.apply_update(bytes(update))&lt;/p&gt;
&lt;p&gt;state_update = ydoc.get_update()
    await sio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` Socket.IO handler checks note ownership only when the `document_id` starts with `note:` (colon). However, the `YdocManager` storage layer normalizes all document IDs by replacing colons with underscores (`document_id.replace(&amp;#34;:&amp;#34;, &amp;#34;_&amp;#34;)`). An attacker can join a document room using `note_&amp;lt;id&amp;gt;` (underscore) instead of `note:&amp;lt;id&amp;gt;` (colon), bypassing the authorization check entirely while accessing the same underlying Yjs document. The server then returns the full document state, leaking the victim&amp;#39;s private note contents.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `ydoc:document:join` handler in `socket/main.py` (line 511) only performs authorization for document IDs matching the `note:` prefix:&lt;/p&gt;
&lt;p&gt;```python
@sio.on(&amp;#34;ydoc:document:join&amp;#34;)
async def ydoc_document_join(sid, data):
    document_id = data[&amp;#34;document_id&amp;#34;]&lt;/p&gt;
&lt;p&gt;if document_id.startswith(&amp;#34;note:&amp;#34;):
        note_id = document_id.split(&amp;#34;:&amp;#34;)[1]
        note = Notes.get_note_by_id(note_id)
        # ... ownership and AccessGrants check ...
        # Returns early if user doesn&amp;#39;t have access&lt;/p&gt;
&lt;p&gt;# If document_id does NOT start with &amp;#34;note:&amp;#34;, execution continues
    # with no authorization check at all&lt;/p&gt;
&lt;p&gt;await YDOC_MANAGER.add_user(document_id=document_id, user_id=sid)
    await sio.enter_room(sid, f&amp;#34;doc_{document_id}&amp;#34;)&lt;/p&gt;
&lt;p&gt;ydoc = Y.Doc()
    updates = await YDOC_MANAGER.get_updates(document_id)
    for update in updates:
        ydoc.apply_update(bytes(update))&lt;/p&gt;
&lt;p&gt;state_update = ydoc.get_update()
    await sio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2712</guid>
    </item>
  </channel>
</rss>
