Impact
Open WebUI before 0.6.27 contains a server‑side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint. Authenticated users can craft URL parameters that trigger location‑redirect headers, allowing the application to reach internal services or other restricted resources. By exploiting this path, an attacker can potentially read sensitive data or eject commands through instance secrets, thereby jeopardizing confidentiality, integrity, and availability of the internal infrastructure.
Affected Systems
The affected product is Open WebUI, version 0.6.27 and earlier. All deployments of open‑webui that have not applied the 0.6.27 update are vulnerable. The vulnerability is tied specifically to the /api/v1/retrieval/process/web API endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the user to be authenticated, but afterward the attacker can freely redirect the application to target internal resources. Given the lack of public exploitation evidence and the moderate score, the likelihood of large‑scale attacks is currently low, yet the potential impact warrants prompt mitigation.
OpenCVE Enrichment