THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3r7g-q6cg-q2vx (medium) — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

[GHSA] GHSA-3r7g-q6cg-q2vx (medium) — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

medgithub_advisoriesPublished 2026-08-04

GHSA-3r7g-q6cg-q2vx Severity: medium CVE: CVE-2026-70491

Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints

## Summary

A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared p

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3r7g-q6cg-q2vx