Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. open-webui
  4. ›
  5. CVE-2026-45666

CVE-2026-45666: Open WebUI has an Indirect Object Reference (IDOR) in user notes

May 14, 2026 (updated May 19, 2026)

The API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data.

References

  • github.com/advisories/GHSA-x3qm-p8hr-3c3h
  • github.com/open-webui/open-webui/commit/de3317e26bb67a2a7ea015a183bbd1d369880ebd
  • github.com/open-webui/open-webui/releases/tag/v0.8.11
  • github.com/open-webui/open-webui/security/advisories/GHSA-x3qm-p8hr-3c3h
  • nvd.nist.gov/vuln/detail/CVE-2026-45666

Code Behaviors & Features

Detect and mitigate CVE-2026-45666 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.8.11

Fixed versions

  • 0.8.11

Solution

Upgrade to version 0.8.11 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

pypi/open-webui/CVE-2026-45666.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:18 +0000.