Open WebUI System Prompt Leakage Vulnerability for Regular Users

Vulnerability

A vulnerability in Open WebUI prior to version 0.8.9 allows regular users (non-admin) to access sensitive system prompts of AI models. When a non-admin user logs in, the application automatically sends a request to the models API. The response includes system prompts for all available models, as set by the admin, thereby compromising application confidentiality.

Impact

This vulnerability allows non-admin users to view system prompts, which can include model instructions and capabilities. Such exposure could enable content manipulation, affecting how the model processes inputs and outputs.

Reproduction

To reproduce this vulnerability, log into the Open WebUI application as a regular user (non-admin). Once logged in, the application will generate a request to the models API. The response to this request will include the system prompts for all models, revealing sensitive information that should not be accessible to non-admin users.

Remediation

Users can update to Open WebUI version 0.8.9 or later, where this vulnerability has been fixed.

Added: May 15, 2026, 10:23 PM
Updated: May 15, 2026, 10:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
7.7
relevance
8.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.