Improper Neutralization of Special Elements in Data Query Logic Affecting open-webui package, versions [,0.9.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Neutralization of Special Elements in Data Query Logic vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-OPENWEBUI-17400348
  • published22 Jun 2026
  • disclosed17 Jun 2026
  • credit0xEr3n

Introduced: 17 Jun 2026

NewCVE-2026-54019  (opens in a new tab)
CWE-862  (opens in a new tab)
CWE-943  (opens in a new tab)

How to fix?

Upgrade open-webui to version 0.9.6 or higher.

Overview

open-webui is an Open WebUI

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Data Query Logic in the resource_id processing in Milvus multitenancy mode. An attacker can access private knowledge-base content belonging to other users by crafting a malicious collection name that bypasses access control checks and is interpolated unsafely into a database expression. This is only exploitable if Milvus multitenancy mode is enabled in the deployment.

CVSS Base Scores

version 4.0
version 3.1