VDB
EN
LOW 3.1

GHSA-73x5-h92w-xc2j

Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding

빠른 조치

GHSA-73x5-h92w-xc2j — open-webui: 아래 명령으로 수정 버전으로 올리세요.

pip install --upgrade 'open-webui>=0.10.0'

상세

## Summary

A normal authenticated user can read the content of a message in a private channel they do not belong to. `GET /api/v1/channels/{id}/messages/{message_id}/thread` authorizes the caller against the URL channel, but the underlying thread lookup loads the thread *parent* by id and returns it without verifying the parent belongs to that channel. By requesting a thread in a channel they can access while supplying a victim channel's message id as the thread root, the attacker receives the victim message — content, channel id, and author.

## Affected component

- `backend/open_webui/models/messages.py` — `get_messages_by_parent_id()` - `backend/open_webui/routers/channels.py` — `get_channel_thread_messages()` (read), `new_message_handler()` (parent/reply binding on write)

## Root cause

`get_messages_by_parent_id(channel_id, parent_id)` filters the thread *replies* by `channel_id`, but loads the thread *parent* by id alone and appends it without requiring `parent.channel_id == channel_id`:

```python message = await db.get(Message, parent_id) # loaded by id only — no channel binding if not message: return [] # replies are filtered by channel_id ... if len(all_messages) < limit: all_messages.append(message) # parent appended unconditionally ```

`get_channel_thread_messages()` authorizes only the URL channel, then calls `get_messages_by_parent_id(id, message_id)` with the caller-supplied `message_id`. The reply insert path (`new_message_handler` → `insert_new_message`) also stored a caller-supplied `parent_id` without binding it to the channel.

## Impact

A non-member can disclose the content (plus channel id and author metadata) of a private-channel message whose id they know or obtain. Direct reads of the victim channel/message/thread return 403; the disclosure is via the thread parent of a channel the attacker can access. Read-only, one message per known id.

## Proof of Concept

(reporter) Validated on v0.9.6: `GET /channels/{attacker_channel}/messages/{victim_message_id}/thread` returned the victim's private message — content, victim channel id, and author — although direct reads of the victim channel returned 403.

## Fix

Bind the thread parent to the requested channel: `get_messages_by_parent_id` returns `[]` unless the parent exists and `parent.channel_id == channel_id`. Defence-in-depth on the write path: `new_message_handler` rejects a supplied `parent_id`/`reply_to_id` whose message does not belong to the URL channel.

## Affected / Patched

- Affected: `< 0.10.0` (last affected release 0.9.6) - Patched: v0.10.0 (PR #25766). `get_messages_by_parent_id` binds the thread parent to the requested channel (returns `[]` unless `parent.channel_id == channel_id`), and `new_message_handler` rejects a caller-supplied `parent_id`/`reply_to_id` whose message does not belong to the channel.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / open-webui
최초 영향 버전: 0 수정 버전: 0.10.0
수정 pip install --upgrade 'open-webui>=0.10.0'

참고