Information Disclosure Vulnerability in Open WebUI by Open WebUI
CVE-2026-54020

6.3MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
4 August 2026

What is CVE-2026-54020?

Open WebUI, a self-hosted AI platform, has an information disclosure vulnerability affecting versions prior to 0.11.0. This issue arises when the platform performs hostname resolution during URL validation, leading to a risky scenario where an attacker can exploit the behavior to gain unauthorized access to internal services. By controlling the authoritative DNS for a specific hostname, an authenticated attacker can provide a public address during validation and subsequently manipulate the connection to point to internal, sensitive resources. This could result in the exposure of cloud metadata, access to loopback admin APIs, or internal services through various functionalities such as URL ingestion and image fetching. The vulnerability is addressed in version 0.11.0.

Affected Version(s)

open-webui < 0.11.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.