CVE-2026-70479

🟡 Monitoruj

Brak walidacji żądań podrzędnych w Open WebUI pozwala na dostęp do zablokowanych adresów wewnętrznych.

CVSS
7.7
EPSS
0.3%
Exploit
poc
Vendor
openwebui
Opis źródłowy (NVD)

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied by an authenticated user can use JavaScript to reach blocked internal addresses, and returned DOM can include data read from those addresses in web-search or RAG output. This issue is fixed in 0.11.0.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-08-04 20:16:54 UTC
Ostatnia modyfikacja (NVD)2026-09-18 14:45:45 UTC
Referencje