CVE-2026-87996
🟡 Monitoruj
Błąd w Open WebUI pozwala na ujawnienie danych wewnętrznych przez kontrolowany DNS.
CVSS
7.7
EPSS
0.2%
Exploit
poc
Vendor
openwebui
Opis źródłowy (NVD)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public address to validation and an internal address to the browser, exposing responses from internal services or cloud metadata through web search or URL ingestion. This issue is fixed in version 0.11.1.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-09 22:18:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 15:14:48 UTC |
Referencje
- https://github.com/open-webui/open-webui/commit/27402ff210bfa253445720920dfb86b15a00327b ([email protected]) [Patch]
- https://github.com/open-webui/open-webui/pull/28634 ([email protected]) [Issue Tracking, Patch]
- https://github.com/open-webui/open-webui/releases/tag/v0.11.1 ([email protected]) [Release Notes]
- https://github.com/open-webui/open-webui/security/advisories/GHSA-4v28-j6q3-5m4r ([email protected]) [Exploit, Vendor Advisory]