PT-2026-54047 · Unknown · Open-Webui

·

CVE-2026-56399

·

Published

2026-06-30

·

Updated

2026-07-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.6.27
Description Authenticated users can bypass server-side request forgery (SSRF) protections—a flaw where a server is tricked into making requests to an unintended location. By manipulating URL parameters with location redirect headers, attackers can access internal services and potentially execute commands using instance secrets via the '/api/v1/retrieval/process/web' endpoint.
Recommendations Update to version 0.6.27 or later. Restrict access to the '/api/v1/retrieval/process/web' endpoint to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56399
GHSA-82R6-C5JM-F3MW

Affected Products

Open-Webui