Junglewise Threat Intelligence

CVE-2026-5803: bigsk1 openai-realtime-ui SSRF in API Proxy Endpoint

CVE-2026-5803 · Severity: medium · CVSS 6.3 · Published 2026-04-08

Executive brief

A security vulnerability was found in the openai-realtime-ui interface, which provides a web-based UI for interacting with OpenAI's Realtime API. An attacker can use a specific part of the application to force the server to make unauthorized requests to other websites or internal systems. This could allow an attacker to access sensitive internal data, bypass firewalls, or interact with private services that are not intended to be public.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the API Proxy Endpoint of openai-realtime-ui (specifically in server.js). The application accepts a user-supplied URL via the 'url' query parameter at the /api/proxy endpoint and passes it directly to the fetch() function without sufficient validation or allowlisting. A remote attacker with network access to the HTTP interface can exploit this to force the server to perform arbitrary outbound requests. This can be used to probe internal network services, access cloud metadata endpoints (e.g., IMDS), or bypass network-level access controls. The issue has been addressed in commit 54f8f50f43af97c334a881af7b021e84b5b8310f by implementing DNS resolution checks and URL hardening.

Affected products

  • bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c

Timeline

  • 2026-03-15: disclosed: Vulnerability reported by researcher BruceJin
  • 2026-03-24: patched: Fix committed to repository (54f8f50)
  • 2026-04-08: advisory: CVE-2026-5803 published

References