Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59222

Опубликовано: 09 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api/v1/channels//members returned full UserModelResponse objects for channel members, including settings.ui.toolServers[].key and webhook configuration, allowing a normal channel participant to retrieve other users’ sensitive settings. This issue is fixed in version 0.10.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
Версия от 0.7.0 (включая) до 0.10.0 (исключая)

EPSS

Процентиль: 24%
0.00322
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

github
около 1 месяца назад

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

EPSS

Процентиль: 24%
0.00322
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200