Open WebUI Chat Completions API Access Control Vulnerability

Vulnerability

A vulnerability in Open WebUI prior to version 0.9.0 allows users to access and continue conversations of other users through the Chat Completions API. This issue arises from a lack of proper ownership verification, enabling any user to manipulate chats as long as they know the Chat ID. The vulnerability could lead to unauthorized access to private conversations and sensitive information.

Impact

Exploitation of this vulnerability allows users to read the conversations of others and access private information, provided they know the Chat ID, which is visible in the chat URL.

Reproduction

To reproduce this vulnerability, sign in to Open WebUI with any user account and generate an API key. Then, create a conversation with another user and copy the Chat ID from the URL. Using the API endpoint '/api/chat/completions' with the Chat ID of the other user, the conversation can be continued, demonstrating the lack of access control.

Remediation

Users can update to Open WebUI version 0.9.0 or later, where this vulnerability has been fixed.

Added: May 15, 2026, 8:22 PM
Updated: May 15, 2026, 8:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.6
remediation
7.7
relevance
8.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.