High
github
·
GHSA-x757-hv69-jr45
Withdrawn Advisory: Open WebUI has SSRF in /openai/models
Published Mar 20, 2025
CVSS 7.7
Withdrawn Advisory
This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references.
Original Description
The /openai/models endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.
Affected AI Products
openai