Redirect Vulnerability in Open WebUI Affects Offline AI Platform
CVE-2026-45401

8.5HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45401?

The Open WebUI platform, designed for offline AI operations, has a vulnerability in its validate_url() function which allows an authenticated user to exploit HTTP 3xx redirects. The vulnerability permits a user to submit a URL that redirects to an internal IP address, potentially gaining access to sensitive internal resources through various API endpoints. The issue was resolved in version 0.9.5, which enhances URL validation against a list of private and metadata IP ranges, thereby safeguarding against unauthorized access.

Affected Version(s)

open-webui < 0.9.5

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.