THREAT OPS › Threat News › [GHSA] GHSA-6xhv-rxhv-pwm4 (medium) — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
[GHSA] GHSA-6xhv-rxhv-pwm4 (medium) — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
GHSA-6xhv-rxhv-pwm4 Severity: medium CVE: CVE-2026-70487
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
## Summary Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points a
Indicators of compromise
- CVE-2026-70487cve
Original source: https://github.com/advisories/GHSA-6xhv-rxhv-pwm4