<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 14:51:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07452</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07452</link>
      <description>bdu:2026-07452</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07452</guid>
    </item>
    <item>
      <title>EUVD-2026-319097</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319097</link>
      <description>EUVD-2026-319097</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319097</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45396</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45396</link>
      <description>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;). Due to an insecure dictionary merge order in insert_new_feedback(), an authenticated attacker can inject a user_id field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing. This vulnerability is fixed in 0.9.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via FeedbackForm, which uses model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;). Due to an insecure dictionary merge order in insert_new_feedback(), an authenticated attacker can inject a user_id field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing. This vulnerability is fixed in 0.9.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45396</guid>
    </item>
    <item>
      <title>GHSA-rjmp-vjf2-qf4g — Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulat…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rjmp-vjf2-qf4g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;)`. Due to an insecure dictionary merge order in `insert_new_feedback()`, an authenticated attacker can inject a `user_id` field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two layers:&lt;/p&gt;
&lt;p&gt;### 1. Model Layer — Insecure Dict Merge Order&lt;/p&gt;
&lt;p&gt;**File:** `backend/open_webui/models/feedbacks.py`, lines 148–160&lt;/p&gt;
&lt;p&gt;```python
async def insert_new_feedback(
    self, user_id: str, form_data: FeedbackForm, db: Optional[AsyncSession] = None
) -&amp;gt; Optional[FeedbackModel]:
    async with get_async_db_context(db) as db:
        id = str(uuid.uuid4())
        feedback = FeedbackModel(
            **{
                &amp;#39;id&amp;#39;: id,
                &amp;#39;user_id&amp;#39;: user_id,       # ← Server-set from auth token
                &amp;#39;version&amp;#39;: 0,
                **form_data.model_dump(),  # ← OVERWRITES &amp;#39;id&amp;#39;, &amp;#39;user_id&amp;#39;, &amp;#39;version&amp;#39;
                &amp;#39;created_at&amp;#39;: int(time.time()),
                &amp;#39;updated_at&amp;#39;: int(time.time()),
            }
        )
```&lt;/p&gt;
&lt;p&gt;In Python, when a dictionary literal contains duplicate keys, the **last value wins…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;)`. Due to an insecure dictionary merge order in `insert_new_feedback()`, an authenticated attacker can inject a `user_id` field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two layers:&lt;/p&gt;
&lt;p&gt;### 1. Model Layer — Insecure Dict Merge Order&lt;/p&gt;
&lt;p&gt;**File:** `backend/open_webui/models/feedbacks.py`, lines 148–160&lt;/p&gt;
&lt;p&gt;```python
async def insert_new_feedback(
    self, user_id: str, form_data: FeedbackForm, db: Optional[AsyncSession] = None
) -&amp;gt; Optional[FeedbackModel]:
    async with get_async_db_context(db) as db:
        id = str(uuid.uuid4())
        feedback = FeedbackModel(
            **{
                &amp;#39;id&amp;#39;: id,
                &amp;#39;user_id&amp;#39;: user_id,       # ← Server-set from auth token
                &amp;#39;version&amp;#39;: 0,
                **form_data.model_dump(),  # ← OVERWRITES &amp;#39;id&amp;#39;, &amp;#39;user_id&amp;#39;, &amp;#39;version&amp;#39;
                &amp;#39;created_at&amp;#39;: int(time.time()),
                &amp;#39;updated_at&amp;#39;: int(time.time()),
            }
        )
```&lt;/p&gt;
&lt;p&gt;In Python, when a dictionary literal contains duplicate keys, the **last value wins…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rjmp-vjf2-qf4g</guid>
    </item>
    <item>
      <title>PYSEC-2026-2756 — Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulat…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2756</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;)`. Due to an insecure dictionary merge order in `insert_new_feedback()`, an authenticated attacker can inject a `user_id` field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two layers:&lt;/p&gt;
&lt;p&gt;### 1. Model Layer — Insecure Dict Merge Order&lt;/p&gt;
&lt;p&gt;**File:** `backend/open_webui/models/feedbacks.py`, lines 148–160&lt;/p&gt;
&lt;p&gt;```python
async def insert_new_feedback(
    self, user_id: str, form_data: FeedbackForm, db: Optional[AsyncSession] = None
) -&amp;gt; Optional[FeedbackModel]:
    async with get_async_db_context(db) as db:
        id = str(uuid.uuid4())
        feedback = FeedbackModel(
            **{
                &amp;#39;id&amp;#39;: id,
                &amp;#39;user_id&amp;#39;: user_id,       # ← Server-set from auth token
                &amp;#39;version&amp;#39;: 0,
                **form_data.model_dump(),  # ← OVERWRITES &amp;#39;id&amp;#39;, &amp;#39;user_id&amp;#39;, &amp;#39;version&amp;#39;
                &amp;#39;created_at&amp;#39;: int(time.time()),
                &amp;#39;updated_at&amp;#39;: int(time.time()),
            }
        )
```&lt;/p&gt;
&lt;p&gt;In Python, when a dictionary literal contains duplicate keys, the **last value wins…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra=&amp;#39;allow&amp;#39;)`. Due to an insecure dictionary merge order in `insert_new_feedback()`, an authenticated attacker can inject a `user_id` field in the request body that overwrites the server-derived value, creating feedback records attributed to any arbitrary user. This corrupts the model evaluation leaderboard (Elo ratings) and enables identity spoofing.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in two layers:&lt;/p&gt;
&lt;p&gt;### 1. Model Layer — Insecure Dict Merge Order&lt;/p&gt;
&lt;p&gt;**File:** `backend/open_webui/models/feedbacks.py`, lines 148–160&lt;/p&gt;
&lt;p&gt;```python
async def insert_new_feedback(
    self, user_id: str, form_data: FeedbackForm, db: Optional[AsyncSession] = None
) -&amp;gt; Optional[FeedbackModel]:
    async with get_async_db_context(db) as db:
        id = str(uuid.uuid4())
        feedback = FeedbackModel(
            **{
                &amp;#39;id&amp;#39;: id,
                &amp;#39;user_id&amp;#39;: user_id,       # ← Server-set from auth token
                &amp;#39;version&amp;#39;: 0,
                **form_data.model_dump(),  # ← OVERWRITES &amp;#39;id&amp;#39;, &amp;#39;user_id&amp;#39;, &amp;#39;version&amp;#39;
                &amp;#39;created_at&amp;#39;: int(time.time()),
                &amp;#39;updated_at&amp;#39;: int(time.time()),
            }
        )
```&lt;/p&gt;
&lt;p&gt;In Python, when a dictionary literal contains duplicate keys, the **last value wins…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2756</guid>
    </item>
  </channel>
</rss>
