THREAT OPS › Threat News › [GHSA] GHSA-5gpj-vj23-vhhv (medium) — Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
[GHSA] GHSA-5gpj-vj23-vhhv (medium) — Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
GHSA-5gpj-vj23-vhhv Severity: medium CVE: CVE-2026-70490
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
## Summary The terminal WebSocket route authenticates its own first-message JWT instead of going through the HTTP dependency chain, and never applies the role check that `get_verified_user` enforces on every HTTP terminal route. An a
Indicators of compromise
- CVE-2026-70490cve
Original source: https://github.com/advisories/GHSA-5gpj-vj23-vhhv