Описание
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public address to validation and an internal address to the browser, exposing responses from internal services or cloud metadata through web search or URL ingestion. This issue is fixed in version 0.11.1.
Ссылки
- Patch
- Issue TrackingPatch
- Release Notes
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.9.6 (включая) до 0.11.1 (исключая)
cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.0021
Низкий
7.7 High
CVSS3
Дефекты
CWE-367
Связанные уязвимости
CVSS3: 7.7
github
12 дней назад
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
EPSS
Процентиль: 12%
0.0021
Низкий
7.7 High
CVSS3
Дефекты
CWE-367