high Open Webui · AI Security

Open WebUI 0.11.4 Patches 19 Advisories, Including Session Token Theft

Data graphic: Open WebUI 0.11.4 patches 19 security advisories, 4 high and 15 medium, none with a CVE id. The highest CVSS score is 8.7, and three of the four high-severity advisories steal session tokens.
NS

Identity security analyst · Updated Oct 2, 2026, 3:28 PM EDT

Open WebUI 0.11.4 fixes 19 advisories, four high-severity and three of them session token theft. None has a CVE id. Upgrade and review sharing rights.

Open WebUI, the self-hosted web interface widely used in front of Ollama and OpenAI-compatible models, has published 19 security advisories dated 27 and 28 September 2026. All of them list version 0.11.4 as the patched release. Four are rated high and 15 medium, and three of the four high-severity advisories let an attacker steal another user's session token. None of the 19 carries a CVE id in the GitHub advisory list, so the GHSA identifiers are the references to track.

Anyone running Open WebUI below 0.11.4 should upgrade. The release itself was published on 21 September 2026, six days before the advisories appeared, and its notes already carry a security advisory line recommending that production deployments update.

The four high-severity advisories

AdvisoryCVSSAffectedSummary
GHSA-f9xp-mfmq-x6cg8.70.11.1 to 0.11.3Script embedded in a DOCX preview steals a viewer's session token
GHSA-vpq8-f445-hcq78.1>= 0.7.0, < 0.11.4A website the user visits can steal a signed-in user's session token
GHSA-q46m-r89w-j74p7.6>= 0.8.6, < 0.11.4Terminal proxy lets users manage Terminals policies and other users' terminals
GHSA-qpqv-xwg8-cqpj7.3>= 0.6.33, < 0.11.4Script link in a shared chat's citation steals a viewer's token

All four scores are CVSS 3.1 base scores as shown in the GitHub advisories.

A website can steal a token (GHSA-vpq8-f445-hcq7)

The advisory, scored 8.1 (CVSS 3.1, network, low complexity, no privileges, user interaction required), describes a message handler in the sync stats modal. It processes cross-origin verify:chat messages without checking who sent them. It concatenates unencoded chat IDs into authenticated API requests, which allows path traversal, and it replies with a target origin of *. A malicious page can therefore make a signed-in user's browser fetch an authenticated endpoint and hand back the response, including the user's session token.

No attacker account or administrator action is needed. The advisory describes the victim as signed in to Open WebUI in the same browser and visiting an attacker-controlled page that opens Open WebUI in a popup. With the token the attacker can replay it against the API as the victim, including reading private chats. The advisory credits reporter @zyakir13 and fix author @Classic298.

The vulnerable handler is mounted only when community sharing is enabled, which is the default (ENABLE_COMMUNITY_SHARING is True). The advisory states that deployments with it set to False are not affected. The 0.11.4 release notes describe the fix as making the statistics window read and reply only where the community site is at the other end.

DOCX preview script (GHSA-f9xp-mfmq-x6cg)

The highest-scored advisory, 8.7, affects only 0.11.1 through 0.11.3. Any approved user who can upload DOCX attachments can craft a file whose embedded content runs in the browser of whoever previews it. The advisory attributes this to the DocxPreview.svelte component, which rendered with default renderer settings that inline a document-supplied HTML part and preserve document-supplied link targets. Sanitization existed only on a fallback branch that the normal render path did not reach.

The script reads the viewer's session token from local storage. If an administrator previews the file, the advisory says the attacker gains full administrative control without a password, including user enumeration, role changes and settings changes. New sign-ups start as pending by default and cannot upload until approved, and the victim must open the shared chat and switch to the Preview view. The advisory lists no workaround and credits @Observerkay as reporter. It was fixed in 0.11.4 by PR #29699.

Terminal proxy (GHSA-q46m-r89w-j74p)

Scored 7.6 and published on 28 September, this one affects deployments that use Open WebUI's Terminals feature. The proxy forwarded any requested path and attached the administrator-configured shared key, so a regular user with access to a Terminals connection could reach the Terminals administrator API. The advisory says an attacker could list other users' terminals, stop a running terminal, read Terminals status and configuration, and create or modify policies. It reports that environment variables set through a changed policy appeared in a second user's terminal when it next started on a connection pinned to that policy.

The preconditions are narrow: the administrator configured the connection with bearer authentication, the connection is not pinned to a named policy, and the Terminals server is older than 0.2.4. Deployments without a Terminals connection are not affected. The advisory documents no workaround, but it notes that Terminals 0.2.4 independently refuses administrator requests that carry a user identity.

Citation link (GHSA-qpqv-xwg8-cqpj)

Scored 7.3, affecting >= 0.6.33 and < 0.11.4. An authenticated attacker stores a javascript: URL in a chat citation's embed_url field and shares the chat. When the victim opens the shared chat and clicks the citation, the script runs in the application's origin and can read localStorage.token. If the victim is an administrator, the compromise extends to administrator capabilities. Version 0.11.4 requires an http or https URL (or a protocol-relative one) before a citation is opened; anything else falls back to the citation modal.

The other 15 are medium severity

The remaining advisories score between 4.2 and 6.5. Several touch the same theme of token and script handling, usually with narrower preconditions than the high-severity four:

  • GHSA-wf9m-46cp-c6h6 (6.4) covers javascript: URLs in chat message links. The attacker needs only the chat sharing permission, which is on by default, but the victim must click the link. Per the advisory, a plain click triggers it in Safari and other WebKit browsers, Firefox needs a middle click or a Ctrl or Shift click, and Chromium-based browsers do not run it.
  • GHSA-9wj4-mcm3-ppj6 (4.6) is a stored XSS through user-authored tool-call embeds in the Markdown renderer. By default the injected script runs in a sandboxed iframe that cannot read the session token; the token is reachable only where an operator has turned on iframeSandboxAllowSameOrigin.
  • GHSA-6g45-8g27-fh8q (6.3) lets a deactivated user keep running commands through an already open terminal WebSocket, though only where an administrator has configured a terminal server.
  • GHSA-gqfh-jxvw-74rp (4.2) covers other users' session tokens disclosed via OAuth-mode connections, tool servers and terminals.

Others cover knowledge-base access, OAuth role handling during token exchange, and denial-of-service paths such as recurrence rules and search patterns that stall workers or exhaust memory. The full list is on the project's advisory page.

What defenders should do

  1. Upgrade to 0.11.4 or later. Four of the advisories cover versions back to 0.6.33 or 0.7.0, so older installs are exposed to several of them at once.
  2. ThreatFrontier's suggestion, not something the advisories prescribe: treat sessions as potentially exposed if an instance was reachable by users who browse the web while signed in, and consider rotating the signing secret and forcing re-login after upgrading. The advisories describe the stolen credential as the session token (JWT) held in browser storage.
  3. If you cannot upgrade immediately, the only documented workaround is setting ENABLE_COMMUNITY_SHARING to False, which addresses GHSA-vpq8-f445-hcq7 alone. For the terminal proxy issue, the advisory documents no workaround.
  4. Review who holds upload, chat-sharing and Terminals access. Several of these flaws need only an ordinary account.
  5. Update any Terminals server to 0.2.4 or later; the proxy advisory lists older servers as a precondition.

This article reports the advisories as published. The advisory pages do not state that any of these flaws has been exploited in the wild, and we found no such claim in the sources reviewed.

Sources

Keep reading

All latest →
  1. highAI SecurityLiteLLM Salt-Key Flaw Lets Any Internal User Forge a Proxy Admin Token and Run Commands5 min
  2. elevatedAI SecurityCoding Agents Can Erase Their Own Audit Trails, and Auto-Mode Monitors Often Miss It5 min
  3. watchAI SecurityAgentXploit Rediscovers Known Agent-Framework Flaws 59% of the Time, Beating Codex at 38%4 min
  4. elevatedAI SecuritySalesBleed: A Public Web Form Let Attackers Pull Agentforce CRM Data Out Over DNS3 min
  5. highAI SecurityAnthropic: Open-Weight GLM-5.3 Nearly Matches Mythos Preview at Writing Exploits3 min
  6. elevatedAI SecurityClaude Code Mods Are On by Default, and They Run Unsandboxed With Your Permissions8 min