THREAT OPS › Threat News › [GHSA] GHSA-8r35-5x5r-hv74 (medium) — Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
[GHSA] GHSA-8r35-5x5r-hv74 (medium) — Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
GHSA-8r35-5x5r-hv74 Severity: medium CVE: CVE-2026-87013
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
## Summary Any authenticated user can move one of their own folders under itself, leaving a loop in their folder tree. The re-parent endpoint performed no check that the new parent was not the folder itself or one of its own subfolders, and the
Indicators of compromise
- CVE-2026-87013cve
Original source: https://github.com/advisories/GHSA-8r35-5x5r-hv74