THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3pf7-q2g3-wj28 (medium) — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

[GHSA] GHSA-3pf7-q2g3-wj28 (medium) — Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

medgithub_advisoriesPublished 2026-09-10

GHSA-3pf7-q2g3-wj28 Severity: medium CVE: CVE-2026-87997

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

## Summary The chat-completions endpoint reads a folder id out of the request body and saves the newly created chat into that folder without checking that the caller is allowed to write there. Any authenticated user who knows a folder's id c

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3pf7-q2g3-wj28