Executive brief
Open WebUI, a self-hosted AI platform, is vulnerable to a security flaw that allows attackers to bypass internal network protections. By providing a specially crafted web link that redirects to internal systems, an attacker can force the AI platform to access private data, cloud credentials, or other internal services that should be restricted. This could lead to the exposure of sensitive infrastructure information or unauthorized access to internal corporate tools.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Open WebUI's SafePlaywrightURLLoader. While the application implements a 'validate_url' function to check user-provided URLs against private IP ranges, this validation is only performed on the initial request. Because the underlying Playwright engine follows HTTP 301/302 redirects by default, an attacker can provide a 'safe' external URL that redirects to a restricted internal address (such as localhost, Docker internal networks, or Cloud Metadata services at 169.254.169.254). This bypasses the 'ENABLE_RAG_LOCAL_WEB_FETCH=False' security setting. The vulnerability is fixed in version 0.9.6 by implementing a request interceptor that validates every URL in the redirect chain.
Affected products
- open-webui Open WebUI < 0.9.6
Timeline
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: NVD publication date
- 2026-06-23: patched: Fix confirmed in version 0.9.6