Server-Side Request Forgery (SSRF) in Open WebUI - #VU140752

 

Server-Side Request Forgery (SSRF) in Open WebUI - #VU140752

Published: August 3, 2026


Vulnerability identifier: #VU140752
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information from internal services reachable by the browser process.

The vulnerability exists due to server-side request forgery (SSRF) in SafePlaywrightURLLoader when processing user-submitted URLs that cause unvalidated sub-resource requests. A remote user can submit a crafted URL for ingestion or trigger a web search to disclose sensitive information from internal services reachable by the browser process.

Only instances using the Playwright web loader are vulnerable, and the returned page DOM can expose data read from reachable internal services through normal web-search or document-ingestion results.


Affected software

Open WebUI

Remediation

Install security update from vendor's website.

Open WebUI - update to 0.11.0

External References

Related Security Bulletins