CVE-2026-70487: Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user’s file id could therefore have the builtin knowledge tools return that file’s indexed content back to them.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-70487 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →