<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 16:05:46 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-45351 — Open WebUI: Exposure of System Prompt to Regular User [Non-Admin]</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-45351</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application. This vulnerability is fixed in 0.8.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; open-webui&lt;/p&gt;
&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.9, when a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application. This vulnerability is fixed in 0.8.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-45351</guid>
    </item>
    <item>
      <title>GHSA-jh9g-8jqw-m2qx — Open WebUI Exposes System Prompt to Regular User [Non-Admin]</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jh9g-8jqw-m2qx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._&lt;/p&gt;
&lt;p&gt;### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_&lt;/p&gt;
&lt;p&gt;### Affected System
_Open WebUI v0.6.40 &amp;#34;main&amp;#34; branch_&lt;/p&gt;
&lt;p&gt;### Vulnerability Details and Advisory from OWASP
LLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/&lt;/p&gt;
&lt;p&gt;### PoC
_1. Regular User [Non-Admin] login on Open WebUI application._
_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._
_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._
&amp;lt;img width=&amp;#34;940&amp;#34; height=&amp;#34;352&amp;#34; alt=&amp;#34;system prompt leak&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Web Request
GET /api/models? HTTP/1.1
Host: localhost:8080
sec-ch-ua-platform: &amp;#34;Linux&amp;#34;
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Accept-Language: en-US,en;q=0.9
sec-ch-ua: &amp;#34;Chromium&amp;#34;;v=&amp;#34;141&amp;#34;, &amp;#34;Not?A_Brand&amp;#34;;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._&lt;/p&gt;
&lt;p&gt;### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_&lt;/p&gt;
&lt;p&gt;### Affected System
_Open WebUI v0.6.40 &amp;#34;main&amp;#34; branch_&lt;/p&gt;
&lt;p&gt;### Vulnerability Details and Advisory from OWASP
LLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/&lt;/p&gt;
&lt;p&gt;### PoC
_1. Regular User [Non-Admin] login on Open WebUI application._
_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._
_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._
&amp;lt;img width=&amp;#34;940&amp;#34; height=&amp;#34;352&amp;#34; alt=&amp;#34;system prompt leak&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;### Web Request
GET /api/models? HTTP/1.1
Host: localhost:8080
sec-ch-ua-platform: &amp;#34;Linux&amp;#34;
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Accept-Language: en-US,en;q=0.9
sec-ch-ua: &amp;#34;Chromium&amp;#34;;v=&amp;#34;141&amp;#34;, &amp;#34;Not?A_Brand&amp;#34;;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jh9g-8jqw-m2qx</guid>
    </item>
  </channel>
</rss>
