OAuth Vulnerability in Open WebUI Artificial Intelligence Platform
CVE-2026-54008
8.5HIGH
What is CVE-2026-54008?
Open WebUI, a self-hosted AI platform, is susceptible to an OAuth-related vulnerability that allows an attacker with a valid identity to exploit URL redirection behavior. In versions prior to 0.9.6, the backend's handling of OAuth picture URLs does not adequately prevent HTTP redirects. When an attacker submits a specially crafted public URL that redirects to an internal address, they can access sensitive information from the internal system through their profile image settings. This significant oversight necessitates immediate attention and remediation.
Affected Version(s)
open-webui < 0.9.6
