Impact
The vulnerability occurs when the tool invocation logic in Open WebUI incorrectly inherits a cookie jar from the main connection loop instead of binding it to each external tool call. When a user sequentially accesses multiple tool servers and the final call uses a bearer‑authenticated server, the user's Open WebUI session cookie can be unintentionally forwarded to that server. The operator of the receiving server can then reuse the cookie to impersonate the user and gain full access to the account, effectively hijacking the session. This flaw turns the Open WebUI session into a credential that can be harvested by any misconfigured external tool.
Affected Systems
The flaw exists in the open‑webui open‑webui product for all releases from version 0.6.27 through 0.11.1 inclusive. The issue was resolved in the 0.11.1 release. Users running any of these versions should verify their configuration of attached tool servers and the version in use.
Risk and Exploitability
With a CVSS score of 6.8, the vulnerability represents a moderately high risk. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Exploitation requires the attacker to control an external tool server that is configured for bearer authentication and to have the victim use Open WebUI to invoke that server. When those conditions are met, an attacker can hijack the session and subsequently take over the user’s account. Until the patch is applied, the vulnerability should be treated as a high‑priority concern.
OpenCVE Enrichment