Server-Side Request Forgery Vulnerability in Open WebUI by Open WebUI
CVE-2025-65958
8.5HIGH
What is CVE-2025-65958?
Open WebUI, a self-hosted AI platform, has a Server-Side Request Forgery (SSRF) vulnerability that enables authenticated users to manipulate server HTTP requests. This flaw can be exploited to target arbitrary URLs, allowing access to cloud metadata endpoints and internal services behind firewalls without requiring advanced permissions. Versions prior to 0.6.37 are susceptible to these operations, which can lead to potential data breaches and unauthorized information access.
Affected Version(s)
open-webui < 0.6.37
