GitHub Repo
Open WebUI Discloses Tool Export Vulnerability; Read-Only Shares May Leak Source Code
Non-admins with tool export permission could download the Python source code of tools shared with them as read-only. The issue was fixed in 0.11.4; operators should review group permissions and check whether credentials are embedded in code.

Open WebUI disclosed a tool export vulnerability on September 27: non-admins with export permission could obtain the Python source code of tools others had shared with them as read-only. The advisory lists affected versions as 0.6.37 through versions before 0.11.4, and rates the severity as moderate. Version 0.11.4 contains the fix. [Security advisory](https://github.com/open-webui/open-webui/security/advisories/GHSA-2h26-836q-4jh2)
The vulnerability was in the bulk export endpoint, `GET /api/v1/tools/export`. The tool details page restricted access to source code, but bulk export still selected tools based on read permission, leaving the same resource protected inconsistently across different APIs. The updated version limits exports to tools the user owns or can write to, matching the rules for exporting a single tool. [Security advisory](https://github.com/open-webui/open-webui/security/advisories/GHSA-2h26-836q-4jh2), [release notes](https://github.com/open-webui/open-webui/releases/tag/v0.11.4)
This affects AI deployments that use tools to connect to internal services. Official documentation says workspace tools are Python code executed within the Open WebUI process; they can call APIs and keep keys on the server. Permission for a user to let a model call a tool does not mean that user should also have access to its implementation. If a team embeds credentials directly in code, a source code leak could expand into a risk of access to backend services. The actual impact depends on the tool’s contents and the credentials’ permissions. [Tools documentation](https://docs.openwebui.com/features/extensibility/plugin/tools/)
Exploitation requires the attacker to be logged in, have tool export permission—which is disabled by default—and have another user’s tool shared with their account or group as read-only. The direct impact described in the advisory is information disclosure; it does not grant the ability to modify or execute tools. [Security advisory](https://github.com/open-webui/open-webui/security/advisories/GHSA-2h26-836q-4jh2)
The patched package was published on September 21, so the news is the public disclosure of the vulnerability details. [PyPI release record](https://pypi.org/project/open-webui/0.11.4/) Operators should check deployed versions and effective permissions. Open WebUI permissions are cumulative: if any group enables export permission, disabling it in another group will not override that setting. Teams that have not upgraded can first revoke export permission from non-admins, but should also check global defaults and every group; hiding the frontend button alone is not sufficient. [Permissions documentation](https://docs.openwebui.com/features/authentication-access/rbac/permissions/)
After upgrading, operators should use a read-only test account to verify bulk export results and check whether any previously shared tools contain embedded credentials. If sensitive values may have been exposed, they should also be revoked or rotated. Developers of agent platforms should include the resource details page, single-item export, and bulk export in regression tests, verifying that each applies consistent authorization checks to source code. Tests should also cover cross-group sharing so they catch the effective outcome of cumulative group permissions, even when a check for a single account passes.