---
id: CVE-2026-59715
aliases:
  - GHSA-gmfw-g93r-vg53
title: >-
  Open WebUI: Unauthenticated WebSocket Access to Collaborative Document
  Handlers (ydoc:awareness:update, ydoc:document:leave)
summary: >-
  Open WebUI: Unauthenticated WebSocket Access to Collaborative Document
  Handlers (ydoc:awareness:update, ydoc:document:leave)
severity: low
cvss: 3.1
cwe:
  - CWE-306
vendor: open-webui
product: open-webui
ecosystem: pip
affected:
  - 'open-webui >= 0.6.16, < 0.10.0'
patched:
  - open-webui 0.10.0
published: '2026-07-24'
updated: '2026-07-24'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-gmfw-g93r-vg53'
references:
  - url: >-
      https://github.com/open-webui/open-webui/security/advisories/GHSA-gmfw-g93r-vg53
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59715'
  - url: 'https://github.com/open-webui/open-webui/pull/25946'
  - url: >-
      https://github.com/open-webui/open-webui/commit/22f2fe1ffb66c993dad1e0b2b35514acaed2370e
  - url: 'https://github.com/open-webui/open-webui/releases/tag/v0.10.0'
  - url: 'https://github.com/advisories/GHSA-gmfw-g93r-vg53'
tags:
  - ghsa
  - pip
epss: 0.00362
epssPercentile: 0.27385
ingestedAt: '2026-07-24T17:34:27.312Z'
---

## Overview

## Summary

The Socket.IO server is configured with `always_connect=True` (lines 78, 91 in `backend/open_webui/socket/main.py`) and the `connect` handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions.

## Vulnerable Code

### `ydoc:awareness:update` (line 741) — No auth check at all
```python
@sio.on('ydoc:awareness:update')
async def yjs_awareness_update(sid, data):
    document_id = data['document_id']
    user_id = data.get('user_id', sid)
    update = data['update']
    # No SESSION_POOL check, no room membership check
    await sio.emit(
        'ydoc:awareness:update',
        {'document_id': document_id, 'user_id': user_id, 'update': update},
        room=f'doc_{document_id}',
        skip_sid=sid,
    )
```

### `ydoc:document:leave` (line 711) — No auth check at all
```python
@sio.on('ydoc:document:leave')
async def yjs_document_leave(sid, data):
    document_id = data['document_id']
    user_id = data.get('user_id', sid)
    # No auth check
    await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid)
    await sio.emit('ydoc:user:left',
        {'document_id': document_id, 'user_id': user_id},
        room=f'doc_{document_id}')
```

### Root Cause: `always_connect=True` (line 78)
```python
sio = socketio.AsyncServer(
    always_connect=True,   # Never rejects connections
    ...
)
```

The `connect` handler (line 329) adds authenticated users to `SESSION_POOL` but never returns `False` or raises an exception for unauthenticated connections.

## Exploitation

1. An unauthenticated attacker connects via Socket.IO (no token needed)
2. The attacker emits `ydoc:awareness:update` with:
   - `document_id`: a known/guessed note UUID (format: `note:{uuid}`)
   - `user_id`: spoofed to impersonate any user
   - `update`: arbitrary awareness data (fake cursor positions, selections)
3. The fake awareness data is broadcast to all legitimate users in the document room
4. The attacker can also emit `ydoc:document:leave` with spoofed `user_id` to broadcast fake `ydoc:user:left` events

## Impact

- **UI disruption**: Fake cursor positions and user presence in collaborative editing sessions
- **User impersonation**: Attacker can spoof any `user_id` in awareness updates
- **Resource exhaustion**: Unlimited unauthenticated WebSocket connections maintained by the server

Note: Other Ydoc handlers (`ydoc:document:join`, `ydoc:document:update`, `ydoc:document:state`) correctly check `SESSION_POOL` membership.

## Suggested Fix

1. Set `always_connect=False` or reject unauthenticated connections in the `connect` handler
2. Add `SESSION_POOL` checks to `ydoc:awareness:update` and `ydoc:document:leave`
3. Add room membership verification before broadcasting to document rooms

---

> **AI Disclosure (per Rule 11):** AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.

## Affected packages

- `open-webui >= 0.6.16, < 0.10.0`

## Remediation

Upgrade to a patched release:

- `open-webui 0.10.0`
