Open WebUI 0.11.4 fixes 19 advisories, four high-severity and three of them session token theft. None has a CVE id. Upgrade and review sharing rights.
Open WebUI, the self-hosted web interface widely used in front of Ollama and OpenAI-compatible models, has published 19 security advisories dated 27 and 28 September 2026. All of them list version 0.11.4 as the patched release. Four are rated high and 15 medium, and three of the four high-severity advisories let an attacker steal another user's session token. None of the 19 carries a CVE id in the GitHub advisory list, so the GHSA identifiers are the references to track.
Anyone running Open WebUI below 0.11.4 should upgrade. The release itself was published on 21 September 2026, six days before the advisories appeared, and its notes already carry a security advisory line recommending that production deployments update.
The four high-severity advisories
| Advisory | CVSS | Affected | Summary |
|---|---|---|---|
| GHSA-f9xp-mfmq-x6cg | 8.7 | 0.11.1 to 0.11.3 | Script embedded in a DOCX preview steals a viewer's session token |
| GHSA-vpq8-f445-hcq7 | 8.1 | >= 0.7.0, < 0.11.4 | A website the user visits can steal a signed-in user's session token |
| GHSA-q46m-r89w-j74p | 7.6 | >= 0.8.6, < 0.11.4 | Terminal proxy lets users manage Terminals policies and other users' terminals |
| GHSA-qpqv-xwg8-cqpj | 7.3 | >= 0.6.33, < 0.11.4 | Script link in a shared chat's citation steals a viewer's token |
All four scores are CVSS 3.1 base scores as shown in the GitHub advisories.
A website can steal a token (GHSA-vpq8-f445-hcq7)
The advisory, scored 8.1 (CVSS 3.1, network, low complexity, no privileges, user interaction required), describes a message handler in the sync stats modal. It processes cross-origin verify:chat messages without checking who sent them. It concatenates unencoded chat IDs into authenticated API requests, which allows path traversal, and it replies with a target origin of *. A malicious page can therefore make a signed-in user's browser fetch an authenticated endpoint and hand back the response, including the user's session token.
No attacker account or administrator action is needed. The advisory describes the victim as signed in to Open WebUI in the same browser and visiting an attacker-controlled page that opens Open WebUI in a popup. With the token the attacker can replay it against the API as the victim, including reading private chats. The advisory credits reporter @zyakir13 and fix author @Classic298.
The vulnerable handler is mounted only when community sharing is enabled, which is the default (ENABLE_COMMUNITY_SHARING is True). The advisory states that deployments with it set to False are not affected. The 0.11.4 release notes describe the fix as making the statistics window read and reply only where the community site is at the other end.
DOCX preview script (GHSA-f9xp-mfmq-x6cg)
The highest-scored advisory, 8.7, affects only 0.11.1 through 0.11.3. Any approved user who can upload DOCX attachments can craft a file whose embedded content runs in the browser of whoever previews it. The advisory attributes this to the DocxPreview.svelte component, which rendered with default renderer settings that inline a document-supplied HTML part and preserve document-supplied link targets. Sanitization existed only on a fallback branch that the normal render path did not reach.
The script reads the viewer's session token from local storage. If an administrator previews the file, the advisory says the attacker gains full administrative control without a password, including user enumeration, role changes and settings changes. New sign-ups start as pending by default and cannot upload until approved, and the victim must open the shared chat and switch to the Preview view. The advisory lists no workaround and credits @Observerkay as reporter. It was fixed in 0.11.4 by PR #29699.
Terminal proxy (GHSA-q46m-r89w-j74p)
Scored 7.6 and published on 28 September, this one affects deployments that use Open WebUI's Terminals feature. The proxy forwarded any requested path and attached the administrator-configured shared key, so a regular user with access to a Terminals connection could reach the Terminals administrator API. The advisory says an attacker could list other users' terminals, stop a running terminal, read Terminals status and configuration, and create or modify policies. It reports that environment variables set through a changed policy appeared in a second user's terminal when it next started on a connection pinned to that policy.
The preconditions are narrow: the administrator configured the connection with bearer authentication, the connection is not pinned to a named policy, and the Terminals server is older than 0.2.4. Deployments without a Terminals connection are not affected. The advisory documents no workaround, but it notes that Terminals 0.2.4 independently refuses administrator requests that carry a user identity.
Citation link (GHSA-qpqv-xwg8-cqpj)
Scored 7.3, affecting >= 0.6.33 and < 0.11.4. An authenticated attacker stores a javascript: URL in a chat citation's embed_url field and shares the chat. When the victim opens the shared chat and clicks the citation, the script runs in the application's origin and can read localStorage.token. If the victim is an administrator, the compromise extends to administrator capabilities. Version 0.11.4 requires an http or https URL (or a protocol-relative one) before a citation is opened; anything else falls back to the citation modal.
The other 15 are medium severity
The remaining advisories score between 4.2 and 6.5. Several touch the same theme of token and script handling, usually with narrower preconditions than the high-severity four:
- GHSA-wf9m-46cp-c6h6 (6.4) covers
javascript:URLs in chat message links. The attacker needs only the chat sharing permission, which is on by default, but the victim must click the link. Per the advisory, a plain click triggers it in Safari and other WebKit browsers, Firefox needs a middle click or a Ctrl or Shift click, and Chromium-based browsers do not run it. - GHSA-9wj4-mcm3-ppj6 (4.6) is a stored XSS through user-authored tool-call embeds in the Markdown renderer. By default the injected script runs in a sandboxed iframe that cannot read the session token; the token is reachable only where an operator has turned on
iframeSandboxAllowSameOrigin. - GHSA-6g45-8g27-fh8q (6.3) lets a deactivated user keep running commands through an already open terminal WebSocket, though only where an administrator has configured a terminal server.
- GHSA-gqfh-jxvw-74rp (4.2) covers other users' session tokens disclosed via OAuth-mode connections, tool servers and terminals.
Others cover knowledge-base access, OAuth role handling during token exchange, and denial-of-service paths such as recurrence rules and search patterns that stall workers or exhaust memory. The full list is on the project's advisory page.
What defenders should do
- Upgrade to 0.11.4 or later. Four of the advisories cover versions back to 0.6.33 or 0.7.0, so older installs are exposed to several of them at once.
- ThreatFrontier's suggestion, not something the advisories prescribe: treat sessions as potentially exposed if an instance was reachable by users who browse the web while signed in, and consider rotating the signing secret and forcing re-login after upgrading. The advisories describe the stolen credential as the session token (JWT) held in browser storage.
- If you cannot upgrade immediately, the only documented workaround is setting
ENABLE_COMMUNITY_SHARINGtoFalse, which addresses GHSA-vpq8-f445-hcq7 alone. For the terminal proxy issue, the advisory documents no workaround. - Review who holds upload, chat-sharing and Terminals access. Several of these flaws need only an ordinary account.
- Update any Terminals server to 0.2.4 or later; the proxy advisory lists older servers as a precondition.
This article reports the advisories as published. The advisory pages do not state that any of these flaws has been exploited in the wild, and we found no such claim in the sources reviewed.