Fiche vulnérabilité
CVE-2026-59213 : faille moyenne openwebui open webui (CVSS 5.0)
Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permission-filtered per-user model lists to share a static cache entry and exposing one user’s model list to another caller during the TTL window. This issue is fixed in version 0.10.0.
En bref
- Sévérité
- Moyenne (CVSS 5.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 9 juil. 2026
- Dernière mise à jour
- 10 juil. 2026
Produits concernés
- openwebui open webui