THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6xhv-rxhv-pwm4 (medium) — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

[GHSA] GHSA-6xhv-rxhv-pwm4 (medium) — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

medgithub_advisoriesPublished 2026-08-04

GHSA-6xhv-rxhv-pwm4 Severity: medium CVE: CVE-2026-70487

Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata

## Summary Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6xhv-rxhv-pwm4