What happened

On September 27, the Open WebUI team published advisory GHSA-f9xp-mfmq-x6cg. In versions 0.11.1 through 0.11.3, a user allowed to upload DOCX files could craft an attachment that executed document-supplied code when another person previewed it in the interface. According to the maintainers, that code could obtain the viewer's session token. If an administrator opened the file, the attacker could gain administrative access to the instance without knowing a password. This is a confirmed product vulnerability, not a report that a particular company's data has been breached.

The fix is in Open WebUI 0.11.4, released September 21: the preview component no longer embeds document-supplied HTML parts and filters unsafe link schemes. A separate advisory, GHSA-vpq8-f445-hcq7, also published September 27, describes another route to session-token theft through the community-sharing message handler. It affects versions from 0.7.0 through 0.11.3 when that feature is enabled, and is also fixed in 0.11.4.

Why this matters to a business

Running the model locally does not automatically secure the web interface. Employees may use Open WebUI to access internal chats, documents and tools. The consequences of a stolen token depend on the victim's role and are wider for an administrator. For a small business, the immediate task is inventory: which instances staff use, which versions run, and who can upload documents or preview attachments.

What to check now

  • Record the version of each instance and upgrade affected deployments to 0.11.4 or later using the normal process, including a backup and integration checks.
  • Until the upgrade, limit DOCX preview by privileged users; for the second issue, check whether community sharing is enabled. These precautions reduce exposure but do not replace the fix.
  • After upgrading, verify sign-in, role boundaries, document access and event logs. If there are signs of compromise, end active sessions and investigate actions under the company's incident process.

The assessment applies to the versions and conditions specified in the official advisories. Those publications do not establish that any particular Russian deployment has been attacked. Image: © Open WebUI Inc.; product screenshot from the official repository, Open WebUI License.