{"id":"CVE-2026-59216","aliases":["GHSA-74h3-cxq7-vc5q","PYSEC-2026-3592"],"url":"https://o3.security/vulnerability/CVE-2026-59216","summary":"Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id","details":"Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learned another socket ID through ydoc:document:join to run code interpreter Python or tools in that user session. This issue is fixed in version 0.10.0.","published":"2026-07-09T16:48:55.663Z","modified":"2026-08-12T03:51:35.038889576Z","cvss":{"score":7.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"open-webui","fixedVersion":"0.10.0"}],"fix":{"url":"https://github.com/open-webui/open-webui/commit/386ac958144dbbbf0aa6e268070d72b681a318aa","label":"open-webui/open-webui@386ac95"},"references":[{"type":"WEB","url":"https://github.com/open-webui/open-webui/releases/tag/v0.10.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59216.json"},{"type":"ADVISORY","url":"https://github.com/open-webui/open-webui/security/advisories/GHSA-74h3-cxq7-vc5q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59216"},{"type":"FIX","url":"https://github.com/open-webui/open-webui/commit/386ac958144dbbbf0aa6e268070d72b681a318aa"},{"type":"FIX","url":"https://github.com/open-webui/open-webui/pull/25763"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.038889576Z"}}