Redirect Vulnerability in Open WebUI Affects Offline AI Platform
CVE-2026-45401
8.5HIGH
What is CVE-2026-45401?
The Open WebUI platform, designed for offline AI operations, has a vulnerability in its validate_url() function which allows an authenticated user to exploit HTTP 3xx redirects. The vulnerability permits a user to submit a URL that redirects to an internal IP address, potentially gaining access to sensitive internal resources through various API endpoints. The issue was resolved in version 0.9.5, which enhances URL validation against a list of private and metadata IP ranges, thereby safeguarding against unauthorized access.
Affected Version(s)
open-webui < 0.9.5
