How to use this reference
Editorial lesson: treat destination, headers and cookies as one immutable request-authority context. Review capture semantics independently of configuration correctness. The advisory identifies 0.11.1 as fixed by binding cookies per connection. Credential isolation should survive changes in connection order.
Before reading
- HTTP credentials, integration boundaries and secure data handling
Context and limits
- Affected versions are >=0.6.27 and <0.11.1. Requires multiple attached tool servers, including a session/system-OAuth connection; exposure depends on shared-state capture during connection processing. Tool servers are not configured by default.
- The recipient is an administrator-registered, partially trusted server. Impersonation, including administrator access, is a stated consequence of session-token disclosure; production compromise is not established.
- Classic298 is credited as reporter. Patch-release date is not established here.
Sources and provenance
- A user's session cookies are sent to tool servers configured for bearer authentication Open WebUI · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.