A AegiFlow
LOWCVSS 3.1EPSS 0.2%

CVE-2026-59715

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Published
2026-07-24
Modified
2026-07-24
EPSS percentile
13%
Aliases
GHSA-gmfw-g93r-vg53
Sources
github-advisory

Summary

## Summary The Socket.IO server is configured with `always_connect=True` (lines 78, 91 in `backend/open_webui/socket/main.py`) and the `connect` handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions. ## Vulnerable Code ### `ydoc:awareness:update` (line 741) — No auth check at all ```python @sio.on('ydoc:awareness:update') async def yjs_awareness_update(sid, data): document_id = data['document_id'] user_id = data.get('user_id', sid) update = data['update'] # No SESSION_POOL check, no room membership check await sio.emit( 'ydoc:awareness:update', {'document_id': document_id, 'user_id': user_id, 'update': update}, room=f'doc_{document_id}', skip_sid=sid, ) ``` ### `ydoc:document:leave` (line 711) — No auth check at all ```python @sio.on('ydoc:document:leave') async def yjs_document_leave(sid, data): document_id = data['document_id'] user_id = data.get('user_id', sid) # No auth check await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid) await sio.emit('ydoc:user:left', {'document_id': document_id, 'user_id': user_id}, room=f'doc_{document_id}') ``` ### Root Cause: `always_connect=True` (line 78) ```python sio = socketio.AsyncServer( always_connect=True, # Never rejects connections ... ) ``` The `connect` handler (line 329) adds authenticated users to `SESSION_POOL` but never returns `False` or raises an exception for unauthenticated connections. ## Exploitation 1. An unauthenticated attacker connects via Socket.IO (no token needed) 2. The attacker emits `ydoc:awareness:update` with: - `document_id`: a known/guessed note UUID (format: `note:{uuid}`) - `user_id`: spoofed to impersonate any user - `update`: arbitrary awareness data (fake cursor positions, selections) 3. The fake awareness data is broadcast to all legitimate users in the document room 4. The attacker can also emit `ydoc:document:leave` with spoofed `user_id` to broadcast fake `ydoc:user:left` events ## Impact - **UI disruption**: Fake cursor positions and user presence in collaborative editing sessions - **User impersonation**: Attacker can spoof any `user_id` in awareness updates - **Resource exhaustion**: Unlimited unauthenticated WebSocket connections maintained by the server Note: Other Ydoc handlers (`ydoc:document:join`, `ydoc:document:update`, `ydoc:document:state`) correctly check `SESSION_POOL` membership. ## Suggested Fix 1. Set `always_connect=False` or reject unauthenticated connections in the `connect` handler 2. Add `SESSION_POOL` checks to `ydoc:awareness:update` and `ydoc:document:leave` 3. Add room membership verification before broadcasting to document rooms --- > **AI Disclosure (per Rule 11):** AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui0.10.0

Remediation: Upgrade to 0.10.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.