<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 12:58:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07440</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07440</link>
      <description>bdu:2026-07440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07440</guid>
    </item>
    <item>
      <title>EUVD-2026-319380</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319380</link>
      <description>EUVD-2026-319380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319380</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45365</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45365</link>
      <description>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models. This vulnerability is fixed in 0.8.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models. This vulnerability is fixed in 0.8.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45365</guid>
    </item>
    <item>
      <title>GHSA-v6qf-75pr-p96m — Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v6qf-75pr-p96m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `generate_chat_completion` route handlers in both `routers/openai.py` and `routers/ollama.py` declare `bypass_filter` as a function parameter:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 937–941:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/chat/completions&amp;#34;)
async def generate_chat_completion(
    request: Request,
    form_data: dict,
    user=Depends(get_verified_user),
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;**`routers/ollama.py`, line 1283–1288:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/api/chat&amp;#34;)
async def generate_chat_completion(
    ...
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;Because FastAPI automatically binds unrecognized function parameters to the query string, any HTTP client can set this value by appending `?bypass_filter=true` to the request URL.&lt;/p&gt;
&lt;p&gt;When `bypass_filter` is true, the access control check is skipped entirely:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 980:**&lt;/p&gt;
&lt;p&gt;```python
if not bypass_filter and user.role == &amp;#34;user&amp;#34;:
    # ACL check — skipped when bypass_filter is True
```&lt;/p&gt;
&lt;p&gt;This parameter is intended for internal use only — the server-side chat pipeline in `utils/chat.py` (lines 238, 253) passes `bypass_filter=True` as a Python function argument when making…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `generate_chat_completion` route handlers in both `routers/openai.py` and `routers/ollama.py` declare `bypass_filter` as a function parameter:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 937–941:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/chat/completions&amp;#34;)
async def generate_chat_completion(
    request: Request,
    form_data: dict,
    user=Depends(get_verified_user),
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;**`routers/ollama.py`, line 1283–1288:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/api/chat&amp;#34;)
async def generate_chat_completion(
    ...
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;Because FastAPI automatically binds unrecognized function parameters to the query string, any HTTP client can set this value by appending `?bypass_filter=true` to the request URL.&lt;/p&gt;
&lt;p&gt;When `bypass_filter` is true, the access control check is skipped entirely:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 980:**&lt;/p&gt;
&lt;p&gt;```python
if not bypass_filter and user.role == &amp;#34;user&amp;#34;:
    # ACL check — skipped when bypass_filter is True
```&lt;/p&gt;
&lt;p&gt;This parameter is intended for internal use only — the server-side chat pipeline in `utils/chat.py` (lines 238, 253) passes `bypass_filter=True` as a Python function argument when making…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v6qf-75pr-p96m</guid>
    </item>
    <item>
      <title>PYSEC-2026-2758 — Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2758</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `generate_chat_completion` route handlers in both `routers/openai.py` and `routers/ollama.py` declare `bypass_filter` as a function parameter:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 937–941:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/chat/completions&amp;#34;)
async def generate_chat_completion(
    request: Request,
    form_data: dict,
    user=Depends(get_verified_user),
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;**`routers/ollama.py`, line 1283–1288:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/api/chat&amp;#34;)
async def generate_chat_completion(
    ...
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;Because FastAPI automatically binds unrecognized function parameters to the query string, any HTTP client can set this value by appending `?bypass_filter=true` to the request URL.&lt;/p&gt;
&lt;p&gt;When `bypass_filter` is true, the access control check is skipped entirely:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 980:**&lt;/p&gt;
&lt;p&gt;```python
if not bypass_filter and user.role == &amp;#34;user&amp;#34;:
    # ACL check — skipped when bypass_filter is True
```&lt;/p&gt;
&lt;p&gt;This parameter is intended for internal use only — the server-side chat pipeline in `utils/chat.py` (lines 238, 253) passes `bypass_filter=True` as a Python function argument when making…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted models.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `generate_chat_completion` route handlers in both `routers/openai.py` and `routers/ollama.py` declare `bypass_filter` as a function parameter:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 937–941:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/chat/completions&amp;#34;)
async def generate_chat_completion(
    request: Request,
    form_data: dict,
    user=Depends(get_verified_user),
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;**`routers/ollama.py`, line 1283–1288:**&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/api/chat&amp;#34;)
async def generate_chat_completion(
    ...
    bypass_filter: Optional[bool] = False,
    ...
):
```&lt;/p&gt;
&lt;p&gt;Because FastAPI automatically binds unrecognized function parameters to the query string, any HTTP client can set this value by appending `?bypass_filter=true` to the request URL.&lt;/p&gt;
&lt;p&gt;When `bypass_filter` is true, the access control check is skipped entirely:&lt;/p&gt;
&lt;p&gt;**`routers/openai.py`, line 980:**&lt;/p&gt;
&lt;p&gt;```python
if not bypass_filter and user.role == &amp;#34;user&amp;#34;:
    # ACL check — skipped when bypass_filter is True
```&lt;/p&gt;
&lt;p&gt;This parameter is intended for internal use only — the server-side chat pipeline in `utils/chat.py` (lines 238, 253) passes `bypass_filter=True` as a Python function argument when making…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2758</guid>
    </item>
  </channel>
</rss>
