Impact
The bug lies in the way the built‑in knowledge search tool handles readable identifiers: it forwards them to a metadata filter, but the search functions in eleven shipped vector back‑ends ignore that filter. An authenticated user can therefore list identifiers, names, and descriptions of knowledge bases that the user is not supposed to see, although the actual document content remains protected. The disclosed information is limited to metadata, but it still leaks potentially sensitive structure and ownership data. The weakness is classified as Information Disclosure (CWE‑200) and Improper Access Control (CWE‑863).
Affected Systems
The issue affects Open WebUI deployments running version 0.7.0 through 0.11.1 of the open‑webui:open‑webui product. Any installation that has an enabled built‑in knowledge tool and uses one of the eleven vector back‑ends shipped with the platform is vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 4.3, placing it in the moderate severity range. EPSS is not available and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The attack vector is local; an authenticated user with normal access to the platform can trigger enumeration of hidden knowledge bases. Because the attacker does not gain direct access to underlying documents, the impact is limited but still valuable to a malicious insider or friend‑of‑user.
OpenCVE Enrichment