Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, Pin/Unpin is a write operation (modifies the message's is_pinned , pinned_by, pinned_at fields), but in standard channels it only checks read permission, allowing users with read-only access to pin/unpin any message. This vulnerability is fixed in 0.9.5.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5gc6-xhv4-2wg6 | Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, Pin/Unpin is a write operation (modifies the message's is_pinned , pinned_by, pinned_at fields), but in standard channels it only checks read permission, allowing users with read-only access to pin/unpin any message. This vulnerability is fixed in 0.9.5. | |
| Title | Open WebUI: An IDOR vulnerability exists in the pin_channel_message API endpoint | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-15T20:36:21.773Z
Reserved: 2026-05-12T00:51:29.087Z
Link: CVE-2026-45386
No data.
Status : Received
Published: 2026-05-15T21:16:37.043
Modified: 2026-05-15T21:16:37.043
Link: CVE-2026-45386
No data.
OpenCVE Enrichment
Updated: 2026-05-15T22:30:06Z
Weaknesses
Github GHSA