Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
계획된 패치 주기 내 조치(60일 이내)
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N상세 설명
Summary
The Socket.IO server is configured with always_connect=True (lines 78, 91 in backend/open_webui/socket/main.py) and the connect handler (line 329) never rejects unauthenticated connections. Two Ydoc event handlers have zero authentication checks, allowing unauthenticated clients to interact with collaborative document sessions.
Vulnerable Code
ydoc:awareness:update (line 741) — No auth check at all
1@sio.on('ydoc:awareness:update') 2async def yjs_awareness_update(sid, data): 3 document_id = data['document_id'] 4 user_id = data.get('user_id', sid) 5 update = data['update'] 6 # No SESSION_POOL check, no room membership check 7 await sio.emit( 8 'ydoc:awareness:update', 9 {'document_id': document_id, 'user_id': user_id, 'update': update},10 room=f'doc_{document_id}',11 skip_sid=sid,12 )ydoc:document:leave (line 711) — No auth check at all
1@sio.on('ydoc:document:leave') 2async def yjs_document_leave(sid, data): 3 document_id = data['document_id'] 4 user_id = data.get('user_id', sid) 5 # No auth check 6 await YDOC_MANAGER.remove_user(document_id=document_id, user_id=sid) 7 await sio.emit('ydoc:user:left', 8 {'document_id': document_id, 'user_id': user_id}, 9 room=f'doc_{document_id}')Root Cause: always_connect=True (line 78)
1sio = socketio.AsyncServer( 2 always_connect=True, # Never rejects connections 3 ... 4)The connect handler (line 329) adds authenticated users to SESSION_POOL but never returns False or raises an exception for unauthenticated connections.
Exploitation
- An unauthenticated attacker connects via Socket.IO (no token needed)
- The attacker emits
ydoc:awareness:updatewith:document_id: a known/guessed note UUID (format:note:{uuid})user_id: spoofed to impersonate any userupdate: arbitrary awareness data (fake cursor positions, selections)
- The fake awareness data is broadcast to all legitimate users in the document room
- The attacker can also emit
ydoc:document:leavewith spoofeduser_idto broadcast fakeydoc:user:leftevents
Impact
- UI disruption: Fake cursor positions and user presence in collaborative editing sessions
- User impersonation: Attacker can spoof any
user_idin awareness updates - Resource exhaustion: Unlimited unauthenticated WebSocket connections maintained by the server
Note: Other Ydoc handlers (ydoc:document:join, ydoc:document:update, ydoc:document:state) correctly check SESSION_POOL membership.
Suggested Fix
- Set
always_connect=Falseor reject unauthenticated connections in theconnecthandler - Add
SESSION_POOLchecks toydoc:awareness:updateandydoc:document:leave - Add room membership verification before broadcasting to document rooms
AI Disclosure (per Rule 11): AI (Claude) was used to assist with source code review, identifying potential vulnerability patterns, and drafting this report. The researcher directed the analysis, selected focus areas, and independently verified all findings against a running v0.8.12 Docker instance using real HTTP requests with two test accounts. The PoCs included are reproducible and were confirmed live before submission.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 6
링크 내용 불러오는 중…