Server-Side Request Forgery (SSRF) in Open WebUI - #VU140757
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause the victim's browser to send attacker-chosen outbound requests and disclose response data from same-origin or CORS-permissive targets.
The vulnerability exists due to server-side request forgery in Vega/Vega-Lite chart rendering when rendering untrusted vega or vega-lite chat content in the viewer's browser. A remote user can place a specially crafted chart specification where the victim will view it to cause the victim's browser to send attacker-chosen outbound requests and disclose response data from same-origin or CORS-permissive targets.
User interaction is required because the victim must open the message containing the crafted chart.