Skip to content

Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution

High severity GitHub Reviewed Published May 10, 2026 in open-webui/open-webui • Updated May 15, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts