Impact
A flaw in Open WebUI’s inline direct model metadata processing allows an authenticated user to supply it with knowledge attachments that are not filtered against the caller’s read privileges. By knowing another user’s file identifier, a requester can trigger the built‑in knowledge tools to return indexed chunks from that file, exposing sensitive contents without altering the underlying knowledge‑base permissions or workspace model validation. This weakness maps to CWE‑862 and results in a confidentiality breach limited to read‑only access.
Affected Systems
The vulnerability affects the Open WebUI product from version 0.8.8 through 0.10.x inclusive; version 0.11.0 and later are not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation activity. The attack requires an authenticated session and knowledge of another user’s file identifier, implying an internal threat or compromised account. Because the disclosure is read‑only and does not compromise other controls, the attack vector is likely limited to privileged users with access to the UI.
OpenCVE Enrichment
Github GHSA