Vulnerability Description
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own chat message without checking whether they own or can read those files. If the attacker then shares that chat and grants themselves read access, has_access_to_file() treats the victim file as accessible through the shared chat, and the file endpoints read or delete the victim file. This vulnerability is fixed in 0.9.6.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | < 0.9.6 |
Related Weaknesses (CWE)
References
- https://github.com/open-webui/open-webui/security/advisories/GHSA-vrhc-3fr6-pc3cExploitVendor AdvisoryMitigation
- https://github.com/open-webui/open-webui/security/advisories/GHSA-vrhc-3fr6-pc3cExploitVendor AdvisoryMitigation
FAQ
What is CVE-2026-54010?
CVE-2026-54010 is a vulnerability with a CVSS score of 8.3 (HIGH). Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own ch...
How severe is CVE-2026-54010?
CVE-2026-54010 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54010?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.