We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, including those of other admin (owner) accounts.
Reserved 2024-07-23 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-284 Improper Access Control
huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1
Support options