Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Medium6.4CVE-2026-54015 · Published Jun 17, 2026 · updated Jul 20, 2026
## Summary Open WebUI's prompt version-history endpoints authorize the `prompt_id` in the URL but then act on caller-supplied history IDs without verifying that the history row belongs to that prompt (`history_entry.prompt_id == prompt.id`). Three operations are affected: - `GET /api/v1/prompts/id/{prompt_id}/history/diff` , returns another prompt's history snapshots (read). - `POST /api/v1/prompts/id/{prompt_id}/update/version` , restores another prompt's snapshot into the caller's prompt, exposing its content (read). - `DELETE /api/v1/prompts/id/{prompt_id}/history/{history_id}` , deletes another prompt's history entry (delete). An authenticated user with access to any prompt they control, plus a victim `prompt_history.id`, can read or delete another user's private prompt history. The single-entry read endpoint (`GET .../history/{history_id}`) already enforces the binding; these three did not. ## Impact Security boundary crossed: prompt confidentiality and integrity. Prompt history snapshots can contain private prompt text, internal instructions, and sensitive variables. With a known victim `prompt_history.id`, an attacker can read another user's snapshot (via the diff e...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | < 0.9.6 | 0.9.6 |
Details and references
## Summary Open WebUI's prompt version-history endpoints authorize the `prompt_id` in the URL but then act on caller-supplied history IDs without verifying that the history row belongs to that prompt (`history_entry.prompt_id == prompt.id`). Three operations are affected: - `GET /api/v1/prompts/id/{prompt_id}/history/diff` , returns another prompt's history snapshots (read). - `POST /api/v1/prompts/id/{prompt_id}/update/version` , restores another prompt's snapshot into the caller's prompt, exposing its content (read). - `DELETE /api/v1/prompts/id/{prompt_id}/history/{history_id}` , deletes another prompt's history entry (delete). An authenticated user with access to any prompt they control, plus a victim `prompt_history.id`, can read or delete another user's private prompt history. The single-entry read endpoint (`GET .../history/{history_id}`) already enforces the binding; these three did not. ## Impact Security boundary crossed: prompt confidentiality and integrity. Prompt history snapshots can contain private prompt text, internal instructions, and sensitive variables. With a known victim `prompt_history.id`, an attacker can read another user's snapshot (via the diff endpoint or by restoring it into their own prompt) and delete another user's history entry. The active prompt row is not destroyed; the delete impact is against version history. Exploitation requires knowing or obtaining victim history UUIDs, so severity depends on adjacent ID exposure. ## Root Cause The route checks read access only for `prompt_id`: ```python # backend/open_webui/routers/prompts.py prompt = await Prompts.get_prompt_by_id(prompt_id, db=db) ... if not ( user.role == 'admin' or prompt.user_id == user.id or await AccessGrants.has_access( user_id=user.id, resource_type='prompt', resource_id=prompt.id, permission='read', db=db, ) ): raise HTTPException(...) ``` But the authorized prompt ID is not passed into the diff sink: ```python # backend/open_webui/routers/prompts.py diff = await PromptHistories.compute_diff(from_id, to_id, db=db) ``` `compute_diff()` fetches both history entries globally by ID and returns their full snapshots: ```python # backend/open_webui/models/prompt_history.py result_from = await db.execute(select(PromptHistory).filter(PromptHistory.id == from_id)) from_entry = result_from.scalars().first() result_to = await db.execute(select(PromptHistory).filter(PromptHistory.id == to_id)) to_entry = result_to.scalars().first() ... return { 'from_snapshot': from_snapshot, 'to_snapshot': to_snapshot, ... } ``` There is no check that `from_entry.prompt_id == prompt_id` or `to_entry.prompt_id == prompt_id`. The same missing binding affects two further endpoints. `POST .../update/version` restores a snapshot fetched globally by `version_id`: ```python # backend/open_webui/models/prompts.py , update_prompt_version history_entry = await PromptHistories.get_history_entry_by_id(version_id, db=session) ... prompt.content = snapshot.get('content', prompt.content) # foreign snapshot copied into caller's prompt prompt.version_id = version_id ``` `DELETE .../history/{history_id}` deletes an entry fetched globally by `history_id`: ```python # backend/open_webui/models/prompt_history.py , delete_history_entry result = await db.execute(select(PromptHistory).filter_by(id=history_id)) entry = result.scalars().first() ... await db.delete(entry) ``` Neither checks `entry.prompt_id == prompt.id`. The single-entry read endpoint (`GET .../history/{history_id}`) does (`history_entry.prompt_id != prompt.id → 404`); these three endpoints were missing it. ## PoC ```python #!/usr/bin/env python3 """ PoC for prompt history diff IDOR. The PoC executes: - the real routers.prompts.get_prompt_diff() route function - the real PromptHistories.compute_diff() implementation Fake model/DB adapters are used only to avoid requiring a running server. The security-sensitiv
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 17 | Open WebUI: Any authenticated user can read other users' private notes via Socket.IO | Medium5.3 | 0.8.11 |
| Jun 17 | Open WebUI: improper access control | Medium6.3 | 0.9.6 |
| Jun 17 | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode | Medium6.5 | 0.9.6 |
| Jun 17 | Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects | High7.7 | 0.9.6 |
| Jun 17 | Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal | High7.7 | 0.9.6 |
| Jun 17 | Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration | Medium4.3 | 0.9.6 |