THREAT OPS › Threat News › [GHSA] GHSA-3r7g-q6cg-q2vx (medium) — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
[GHSA] GHSA-3r7g-q6cg-q2vx (medium) — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
GHSA-3r7g-q6cg-q2vx Severity: medium CVE: CVE-2026-70491
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
## Summary
A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared p
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-70491cve
Original source: https://github.com/advisories/GHSA-3r7g-q6cg-q2vx