{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-70491", "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "state": "PUBLISHED", "assignerShortName": "GitHub_M", "dateReserved": "2026-08-04T15:24:41.340Z", "datePublished": "2026-08-04T20:51:27.840Z", "dateUpdated": "2026-08-04T20:51:27.840Z" }, "containers": { "cna": { "title": "Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-200", "lang": "en", "description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" } } ], "references": [ { "name": "https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx", "tags": [ "x_refsource_CONFIRM" ], "url": "https://github.com/open-webui/open-webui/security/advisories/GHSA-3r7g-q6cg-q2vx" }, { "name": "https://github.com/open-webui/open-webui/pull/27005", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/open-webui/open-webui/pull/27005" }, { "name": "https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/open-webui/open-webui/commit/c05de13b4fca1ac8a17153782b46b3d0aacf491c" }, { "name": "https://github.com/open-webui/open-webui/releases/tag/v0.11.0", "tags": [ "x_refsource_MISC" ], "url": "https://github.com/open-webui/open-webui/releases/tag/v0.11.0" } ], "affected": [ { "vendor": "open-webui", "product": "open-webui", "versions": [ { "version": "< 0.11.0", "status": "affected" } ] } ], "providerMetadata": { "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M", "dateUpdated": "2026-08-04T20:51:27.840Z" }, "descriptions": [ { "lang": "en", "value": "Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read-only users. ToolResponse deliberately omitted source and specs, but ToolUserResponse permitted extra fields and handlers spread a full tool model dump into the response, re-admitting omitted fields. A non-admin with a read grant can obtain another user's server-side tool source, which commonly embeds hard-coded API keys, credentials, and internal service URLs. This issue is fixed in 0.11.0." } ], "source": { "advisory": "GHSA-3r7g-q6cg-q2vx", "discovery": "UNKNOWN" } } } }