From b147b33ee25b9848015da4f639316bde43db8504 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sat, 6 Jun 2026 16:45:06 +0200 Subject: [PATCH] fix: scope Socket.IO event-caller to the requesting user's own session get_event_call() routed execute:python / execute:tool events to a client-supplied session_id after only checking the session was connected, not that it belonged to the requester. Verify the target session is owned by the requesting user (metadata user_id) before delivering, so a client cannot route code/tool execution into another user's session. Co-Authored-By: Claude Opus 4.8 (1M context) --- backend/open_webui/socket/main.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/backend/open_webui/socket/main.py b/backend/open_webui/socket/main.py index 2884847a0e..89d9ced221 100644 --- a/backend/open_webui/socket/main.py +++ b/backend/open_webui/socket/main.py @@ -1015,9 +1015,10 @@ async def get_event_call(request_info): async def __event_caller__(event_data): session_id = request_info['session_id'] - # Fast-fail if the client has disconnected. - if session_id not in SESSION_POOL: - log.warning(f'Event caller: session {session_id} no longer connected') + # session_id is client-supplied; only the requesting user's own live session may be targeted. + session = SESSION_POOL.get(session_id) + if session is None or session.get('id') != request_info.get('user_id'): + log.warning(f'Event caller: session {session_id} not owned by requesting user or disconnected') return {'error': 'Client session disconnected.'} try: