Vulnerability Description
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as /api/v1/tasks/moa/completions. The normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selected underlying model. The task routes call utils.chat.generate_chat_completion() directly. In that direct path, arena fallback resolution happens after the wrapper access check and then recurses with bypass_filter=True, skipping the selected submodel's access check. This issue is fixed in version 0.10.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openwebui | Open Webui | >= 0.8.12, < 0.10.0 |
Related Weaknesses (CWE)
References
- https://github.com/open-webui/open-webui/commit/dc4924b66e655b315e3be4430a3e51b7Patch
- https://github.com/open-webui/open-webui/pull/26046Issue TrackingPatch
- https://github.com/open-webui/open-webui/releases/tag/v0.10.0ProductRelease Notes
- https://github.com/open-webui/open-webui/security/advisories/GHSA-m3qf-58wf-w979MitigationVendor Advisory
FAQ
What is CVE-2026-59225?
CVE-2026-59225 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an authenticated non-admin user with read access to an arena wrapper model can reach a ...
How severe is CVE-2026-59225?
CVE-2026-59225 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59225?
Check the references section above for vendor advisories and patch information. Affected products include: Openwebui Open Webui.