---
id: CVE-2026-45351
aliases:
  - GHSA-jh9g-8jqw-m2qx
  - PYSEC-2026-2741
title: 'Open WebUI Exposes System Prompt to Regular User [Non-Admin]'
summary: 'Open WebUI Exposes System Prompt to Regular User [Non-Admin]'
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: open-webui
product: open-webui
ecosystem: pip
affected:
  - open-webui < 0.8.9
patched:
  - open-webui 0.8.9
published: '2026-05-14'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jh9g-8jqw-m2qx'
references:
  - url: >-
      https://github.com/open-webui/open-webui/security/advisories/GHSA-jh9g-8jqw-m2qx
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45351'
  - url: 'https://github.com/open-webui/open-webui'
  - url: 'https://github.com/open-webui/open-webui/releases/tag/v0.8.9'
tags:
  - osv
  - pip
epss: 0.00392
epssPercentile: 0.30491
ingestedAt: '2026-07-13T18:57:59.773Z'
---

## Overview

### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._

### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt of available models set by admin on models pages in workspace affecting the confidentiality of application_

### Affected System
_Open WebUI v0.6.40 "main" branch_

### Vulnerability Details and Advisory from OWASP
LLM07:2025 System Prompt Leakage - https://genai.owasp.org/llmrisk/llm072025-system-prompt-leakage/


### PoC
_1. Regular User [Non-Admin] login on Open WebUI application._
_2. A series of web requests get generated by the application, and the http://IP:8080/api/models? is also gets generated by application ._
_3. The response of http://IP:8080/api/models? web request reveals the system prompt of all the available models which is set is by the admin on models pages in workspace._
<img width="940" height="352" alt="system prompt leak" src="https://github.com/user-attachments/assets/bd2c76f1-398f-4bc8-a8b2-5e14a768c560" />

### Web Request
GET /api/models? HTTP/1.1
Host: localhost:8080
sec-ch-ua-platform: "Linux"
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Accept-Language: en-US,en;q=0.9
sec-ch-ua: "Chromium";v="141", "Not?A_Brand";v="8"
sec-ch-ua-mobile: ?0
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
Accept: application/json
Content-Type: application/json
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: http://localhost:8080/
Accept-Encoding: gzip, deflate, br
Cookie: token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjdmYjUxMmFhLTBmMTAtNDRkZi1iOWY1LThmNDg2MWFhNWFmOCIsImV4cCI6MTc2NjU2MjE5OH0.yJpavBynKItPQv76SMGKK012JIf29PVUv9sjuCDuRGQ
Connection: keep-alive


### Impact
_1. System prompts can reveal the model instructions, providing an attackers with inside knowledge about the system capabilities and bypass restrictions._
_2. Attacker can perform content manipulation affecting the input/output of the model._

### Details from MITRE ATLAS
Discover LLM System Information - https://atlas.mitre.org/techniques/AML.T0069
Discover LLM System Information: System Instruction Keywords - https://atlas.mitre.org/techniques/AML.T0069.001
Discover LLM System Information: System Prompt - https://atlas.mitre.org/techniques/AML.T0069.002


### Recommendation
_1. The web response should not reveal system prompt and related internal/back-end details regarding the model to the regular user._
_2. Only the model name and non-sensitive details should be revealed to regular user and internal/back-end details should not be disclosed._

## Affected packages

- `open-webui < 0.8.9`

## Remediation

Upgrade to a patched release:

- `open-webui 0.8.9`
