Redirect Vulnerability in Open WebUI Affects Offline AI Platform
CVE-2026-45401
8.5HIGH
Key Information:
- Vendor
Open-webui
- Status
- Vendor
- CVE Published:
- 15 May 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-45401?
The Open WebUI platform, designed for offline AI operations, has a vulnerability in its validate_url() function which allows an authenticated user to exploit HTTP 3xx redirects. The vulnerability permits a user to submit a URL that redirects to an internal IP address, potentially gaining access to sensitive internal resources through various API endpoints. The issue was resolved in version 0.9.5, which enhances URL validation against a list of private and metadata IP ranges, thereby safeguarding against unauthorized access.
Affected Version(s)
open-webui < 0.9.5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
