Information Disclosure Vulnerability in Open WebUI by Open WebUI
CVE-2026-54020
What is CVE-2026-54020?
Open WebUI, a self-hosted AI platform, has an information disclosure vulnerability affecting versions prior to 0.11.0. This issue arises when the platform performs hostname resolution during URL validation, leading to a risky scenario where an attacker can exploit the behavior to gain unauthorized access to internal services. By controlling the authoritative DNS for a specific hostname, an authenticated attacker can provide a public address during validation and subsequently manipulate the connection to point to internal, sensitive resources. This could result in the exposure of cloud metadata, access to loopback admin APIs, or internal services through various functionalities such as URL ingestion and image fetching. The vulnerability is addressed in version 0.11.0.
Affected Version(s)
open-webui < 0.11.0
