OAuth Vulnerability in Open WebUI Artificial Intelligence Platform
CVE-2026-54008

8.5HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
23 June 2026

What is CVE-2026-54008?

Open WebUI, a self-hosted AI platform, is susceptible to an OAuth-related vulnerability that allows an attacker with a valid identity to exploit URL redirection behavior. In versions prior to 0.9.6, the backend's handling of OAuth picture URLs does not adequately prevent HTTP redirects. When an attacker submits a specially crafted public URL that redirects to an internal address, they can access sensitive information from the internal system through their profile image settings. This significant oversight necessitates immediate attention and remediation.

Affected Version(s)

open-webui < 0.9.6

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.