Skip to content

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Low severity GitHub Reviewed Published Jul 2, 2026 in open-webui/open-webui • Updated Jul 24, 2026

Package

pip open-webui (pip)

Affected versions

>= 0.6.16, < 0.10.0

Patched versions

0.10.0

Description

Summary

The Socket.IO server is configured with always_connect=True (lines 78, 91 in backend/open_webui/socket/main.py) and the connect handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions.

Vulnerable Code

ydoc:awareness:update (line 741) — No auth check at all

@sio.on('ydoc:awareness:update')
async def yjs_awareness_update(sid, data):
    document_id = data['document_id']
    user_id = data.get('user_id', sid)
    update = data['update']
    # No SESSION_POOL check, no room membership check
    await sio.emit(
        'ydoc:awareness:update',
        {'document_id': document_id, 'user_id': user_id, 'update': update},
        room=f'doc_{document_id}',
        skip_sid=sid,
    )

ydoc:document:leave (line 711) — No auth check at all

@sio.on('ydoc:document:leave')
async def yjs_document_leave(sid, data):
    document_id = data['document_id']
    user_id = data.get('user_id', sid)
    # No auth check
    await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid)
    await sio.emit('ydoc:user:left',
        {'document_id': document_id, 'user_id': user_id},
        room=f'doc_{document_id}')

Root Cause: always_connect=True (line 78)

sio = socketio.AsyncServer(
    always_connect=True,   # Never rejects connections
    ...
)

The connect handler (line 329) adds authenticated users to SESSION_POOL but never returns False or raises an exception for unauthenticated connections.

Exploitation

  1. An unauthenticated attacker connects via Socket.IO (no token needed)
  2. The attacker emits ydoc:awareness:update with:
    • document_id: a known/guessed note UUID (format: note:{uuid})
    • user_id: spoofed to impersonate any user
    • update: arbitrary awareness data (fake cursor positions, selections)
  3. The fake awareness data is broadcast to all legitimate users in the document room
  4. The attacker can also emit ydoc:document:leave with spoofed user_id to broadcast fake ydoc:user:left events

Impact

  • UI disruption: Fake cursor positions and user presence in collaborative editing sessions
  • User impersonation: Attacker can spoof any user_id in awareness updates
  • Resource exhaustion: Unlimited unauthenticated WebSocket connections maintained by the server

Note: Other Ydoc handlers (ydoc:document:join, ydoc:document:update, ydoc:document:state) correctly check SESSION_POOL membership.

Suggested Fix

  1. Set always_connect=False or reject unauthenticated connections in the connect handler
  2. Add SESSION_POOL checks to ydoc:awareness:update and ydoc:document:leave
  3. Add room membership verification before broadcasting to document rooms

AI Disclosure (per Rule 11): AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.

References

@doge-woof doge-woof published to open-webui/open-webui Jul 2, 2026
Published by the National Vulnerability Database Jul 9, 2026
Published to the GitHub Advisory Database Jul 24, 2026
Reviewed Jul 24, 2026
Last updated Jul 24, 2026

Severity

Low

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS score

Exploit Prediction Scoring System (EPSS)

This score estimates the probability of this vulnerability being exploited within the next 30 days. Data provided by FIRST.
(13th percentile)

Weaknesses

Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Learn more on MITRE.

CVE ID

CVE-2026-59715

GHSA ID

GHSA-gmfw-g93r-vg53

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.