CVE-2026-87996
Undergoing Analysis Undergoing Analysis - In Progress

Open WebUI SSRF via Playwright URL Loader

Vulnerability report for CVE-2026-87996, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: GitHub, Inc.

Description

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public address to validation and an internal address to the browser, exposing responses from internal services or cloud metadata through web search or URL ingestion. This issue is fixed in version 0.11.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open_webui safeplaywrighturlloader From 0.9.6 (inc) to 0.11.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Open WebUI versions 0.9.6 to 0.11.0 contain a vulnerability in SafePlaywrightURLLoader where user-controlled hostnames are validated in Python but then resolved again by the Playwright browser. An attacker with authenticated access and control over DNS could manipulate this to expose internal service responses or cloud metadata through web search or URL ingestion.

Detection Guidance

This vulnerability requires checking if Open WebUI versions between 0.9.6 and 0.11.1 are installed and if SafePlaywrightURLLoader is enabled. No specific commands are provided in the context to detect exploitation attempts. Verify the installed version with: pip show open-webui. If vulnerable, upgrade to 0.11.1 or later.

Impact Analysis

This vulnerability allows authenticated users to access internal services or sensitive metadata by tricking the system into resolving internal addresses. It could lead to unauthorized data exposure, information leakage, or potential access to confidential resources within your network.

Compliance Impact

This vulnerability could expose internal services or sensitive data through web search or URL ingestion, potentially violating data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., exposure of protected health information). The issue allows authenticated users to manipulate DNS resolution, bypassing intended access controls.

Mitigation Strategies

Upgrade Open WebUI to version 0.11.1 or later to address the vulnerability in SafePlaywrightURLLoader.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87996. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart