HIGH 7.7
GHSA-x757-hv69-jr45
Open WebUI has SSRF in /openai/models
Details
The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / open-webui
Introduced in:
0 No fixed version published yet for open-webui (pip). Pin to a known-safe version or switch to an alternative.