CVE-2026-45350 | open-webui Open WebUI up to 0.8.5 chat_completion tool_ids authorization (GHSA-4pcg-253r-rf9w)
A vulnerability, which was classified as critical, was found in open-webui Open WebUI up to 0.8.5. This impacts the function chat_completion. The manipulation of the argument tool_ids results in missing authorization.
This vulnerability is identified as CVE-2026-45350. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.