Cross-site request forgery in Open WebUI - #VU130938
Published: May 11, 2026
Open WebUI
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service and disclose sensitive information.
The vulnerability exists due to improper input validation in image uploading and rendering functionality when processing user-supplied image urls. A remote user can set an image url to a malicious endpoint to cause a denial of service and disclose sensitive information.
User interaction is required, as a victim must view the compromised image, such as in a profile picture, shared chat, shared note, or model image.