CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-73x5-h92w-xc2j: Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

lowCVSS 3.1CVE-2026-59215
Summary A normal authenticated user can read the content of a message in a private channel they do not belong to. GET /api/v1/channels/{id}/messages/{message_id}/thread authorizes the caller against the URL channel, but the underlying thread lookup loads the thread *parent* by id and returns it without verifying the parent belongs to that channel. By requesting a thread in a channel they can access while supplying a victim channel's message id as the thread root, the attacker receives the victim message — content, channel id, and author. Affected component - backend/open_webui/models/messages.py — get_messages_by_parent_id() - backend/open_webui/routers/channels.py — get_channel_thread_messages() (read), new_message_handler() (parent/reply binding on write) Root cause get_messages_by_parent_id(channel_id, parent_id) filters the thread *replies* by channel_id, but loads the thread *parent* by id alone and appends it without requiring parent.channel_id == channel_id: message = await db.get(Message, parent_id) # loaded by id only — no channel binding if not message: return [] replies are filtered by channel_id ... if len(all_messages) < limit: all_messages.append(message) # parent appended unconditionally get_channel_thread_messages() authorizes only the URL channel, then calls get_messages_by_parent_id(id, message_id) with the caller-supplied message_id. The reply insert path (new_message_handler → insert_new_message) also stored a caller-supplied parent_id without binding it to the channel. Impact A non-member can disclose the content (plus channel id and author metadata) of a private-channel message whose id they know or obtain. Direct reads of the victim channel/message/thread return 403; the disclosure is via the thread parent of a channel the attacker can access. Read-only, one message per known id. Proof of Concept (reporter) Validated on v0.9.6: GET /channels/{attacker_channel}/messages/{victim_message_id}/thread returned the victim's private message

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
low — CVSS 3.1
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-73x5-h92w-xc2j

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-59215coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories