Server-Side Request Forgery (SSRF) in Open WebUI - CVE-2025-65958
Published: April 24, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to access internal services and disclose sensitive information.
The vulnerability exists due to server-side request forgery (ssrf) in /api/v1/retrieval/process/web when processing a user-supplied URL. A remote user can send a specially crafted request containing an arbitrary URL to access internal services and disclose sensitive information.
No special permissions beyond basic authentication are required, and cloud metadata endpoints may be reachable in affected deployments.