Executive brief
Open WebUI, an interface for interacting with large language models, is vulnerable to a security flaw in its web search and image processing features. An authenticated user can trick the server into making requests to internal network addresses that should be restricted, such as private cloud metadata services or internal databases. This could allow an attacker to steal sensitive cloud credentials or access private internal systems, potentially leading to a broader breach of the organization's infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Open WebUI's `validate_url()` function within `backend/open_webui/retrieval/web/utils.py`. The root cause is a failure in the `validators` library where `validators.ipv6(ip, private=True)` raises a `ValidationError` because the `private` keyword is not supported for IPv6; this exception is falsy in a boolean context, causing all IPv6 addresses to pass the filter. Additionally, the validation logic fails to account for IPv4-mapped IPv6 addresses (e.g., `::ffff:10.0.0.1`) and several reserved IPv4 ranges. An authenticated attacker can exploit this to reach internal services, including AWS IMDSv1 for credential exfiltration. The issue is patched in version 0.9.0 by implementing more robust validation using the standard `ipaddress` library.
Affected products
- Open WebUI Open WebUI <= 0.8.12
Timeline
- 2024-09-11: disclosed: Original identification of the vulnerability by Dor Konis
- 2026-05-09: patched: Version 0.9.0 released
- 2026-05-14: advisory: GHSA-4v7r-f4w8-8972 published