Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
—
Published, fixed and credited. Root cause, the vulnerable code, reproduction and the fix, as published in the advisory itself.
| Advisory | GHSA-gmfw-g93r-vg53 |
| CVE | CVE-2026-59715 |
| Severity | Low (3.1) |
| CVSS vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CWE | CWE-306 (Missing Authentication for Critical Function) |
| Published | 2026-07-24 |
| Package | Ecosystem | Vulnerable | Fixed in |
|---|---|---|---|
open-webui | pip | >= 0.6.16, < 0.10.0 | 0.10.0 |
The Socket.IO server is configured with always_connect=True (lines 78, 91 in backend/open_webui/socket/main.py) and the connect handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions.
ydoc:awareness:update (line 741) — No auth check at all@sio.on('ydoc:awareness:update')
async def yjs_awareness_update(sid, data):
document_id = data['document_id']
user_id = data.get('user_id', sid)
update = data['update']
# No SESSION_POOL check, no room membership check
await sio.emit(
'ydoc:awareness:update',
{'document_id': document_id, 'user_id': user_id, 'update': update},
room=f'doc_{document_id}',
skip_sid=sid,
)
ydoc:document:leave (line 711) — No auth check at all@sio.on('ydoc:document:leave')
async def yjs_document_leave(sid, data):
document_id = data['document_id']
user_id = data.get('user_id', sid)
# No auth check
await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid)
await sio.emit('ydoc:user:left',
{'document_id': document_id, 'user_id': user_id},
room=f'doc_{document_id}')
always_connect=True (line 78)sio = socketio.AsyncServer(
always_connect=True, # Never rejects connections
...
)
The connect handler (line 329) adds authenticated users to SESSION_POOL but never returns False or raises an exception for unauthenticated connections.
ydoc:awareness:update with: document_id: a known/guessed note UUID (format: note:{uuid})user_id: spoofed to impersonate any userupdate: arbitrary awareness data (fake cursor positions, selections)ydoc:document:leave with spoofed user_id to broadcast fake ydoc:user:left eventsuser_id in awareness updatesNote: Other Ydoc handlers (ydoc:document:join, ydoc:document:update, ydoc:document:state) correctly check SESSION_POOL membership.
always_connect=False or reject unauthenticated connections in the connect handlerSESSION_POOL checks to ydoc:awareness:update and ydoc:document:leaveAI Disclosure (per Rule 11): AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.
Sanaan Fayaz Wani (GitHub sfwani) reported this vulnerability to the open-webui maintainers under coordinated disclosure and is credited as a reporter in GHSA-gmfw-g93r-vg53, published 2026-07-24.
All published findings: advisory index.