CVE-2026-59213
EUVD-2026-4262909.07.2026, 17:17
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, causing permission-filtered per-user model lists to share a static cache entry and exposing one user’s model list to another caller during the TTL window. This issue is fixed in version 0.10.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openwebui | open_webui | 0.6.27 ≤ 𝑥 < 0.10.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References