From 386ac958144dbbbf0aa6e268070d72b681a318aa Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Mon, 29 Jun 2026 09:17:40 +0200 Subject: [PATCH] fix: scope Socket.IO event-caller to the requesting user's own session (#25763) get_event_call() routed execute:python / execute:tool events to a client-supplied session_id after only checking the session was connected, not that it belonged to the requester. Verify the target session is owned by the requesting user (metadata user_id) before delivering, so a client cannot route code/tool execution into another user's session. Co-authored-by: Claude Opus 4.8 (1M context) --- backend/open_webui/socket/main.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/backend/open_webui/socket/main.py b/backend/open_webui/socket/main.py index 3333377885..2be8153887 100644 --- a/backend/open_webui/socket/main.py +++ b/backend/open_webui/socket/main.py @@ -1022,9 +1022,10 @@ async def get_event_call(request_info): async def __event_caller__(event_data): session_id = request_info['session_id'] - # Fast-fail if the client has disconnected. - if session_id not in SESSION_POOL: - log.warning(f'Event caller: session {session_id} no longer connected') + # session_id is client-supplied; only the requesting user's own live session may be targeted. + session = SESSION_POOL.get(session_id) + if session is None or session.get('id') != request_info.get('user_id'): + log.warning(f'Event caller: session {session_id} not owned by requesting user or disconnected') return {'error': 'Client session disconnected.'} try: