Open WebUI Package Discloses Tool Source Code to Read-Only Users
Reportedly, the Open WebUI package disclosed Python source code to read-only users, potentially exposing sensitive information.
What happened
The Open WebUI package, specifically versions prior to 0.11.0, appears to have exposed Python source code to authenticated non-admin users through the tool list and get endpoints. This vulnerability allowed read-only users to access the source code of shared tools, which could potentially reveal sensitive information. To assess your exposure, check if you are using a version of Open WebUI prior to 0.11.0. It is recommended to upgrade to version 0.11.0 or later to mitigate this issue. For more details, consult the primary sources listed below.
The vulnerability is tracked under GHSA-3R7G-Q6CG-Q2VX and is under investigation. It is important to note that this is an early warning and the extent of the compromise is not yet fully confirmed. Users of Open WebUI should review their configurations and ensure they are running a secure version of the package. Additional information can be found in the GitHub security advisories linked in the sources section.
How 0Day mitigates this
open webui is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.