Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
High severity
GitHub Reviewed
Published
May 10, 2026
in
open-webui/open-webui
•
Updated May 15, 2026
Give feedback on Dependabot alerts