THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p78m-89r6-pgf7 (medium) — Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

[GHSA] GHSA-p78m-89r6-pgf7 (medium) — Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

medgithub_advisoriesPublished 2026-09-10

GHSA-p78m-89r6-pgf7 Severity: medium CVE: CVE-2026-87015

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

## Summary

When more than one external tool server is reachable in the same request, a tool call to a server configured for bearer authentication can arrive carrying the calling user's Open WebUI session cookies alongside that server's own k

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p78m-89r6-pgf7