Impact
Open WebUI releases 0.9.0 through 0.11.0 incorrectly filtered URL destinations, permitting authenticated users to embed internal IPv4 addresses within NAT64 well‑known prefixes. The application then processed these URLs in RAG ingestion, URL‑to‑markdown conversion, or web‑search content retrieval, returning the internal response body to the user. This flaw allows users to read data from internal services and cloud‑metadata endpoints, effectively leaking sensitive internal information.
Affected Systems
The vulnerability affects the Open WebUI product from the open-webui vendor, specifically versions 0.9.0 up to and including 0.11.0. Any deployment that runs one of these versions behind a NAT64 gateway is susceptible.
Risk and Exploitability
The flaw carries a CVSS score of 7.1. No EPSS score is provided, and it is not listed in the CISA KEV catalog, indicating a moderate likelihood of exploitation. The attack requires a verified user with access to submit URLs and a NAT64‑enabled network, and an attacker can craft a NAT64‑encoded IPv4 address targeting an internal service or metadata endpoint to retrieve its response. The impact is limited to internal data leakage, not full remote code execution.
OpenCVE Enrichment
Github GHSA