Impact
An authenticated user of Open WebUI can cause the server to perform a web request to the Azure internal IP 168.63.129.16 via the POST /api/v1/retrieval/process/web and /api/v1/retrieval/process/web/search endpoints. This Server‑Side Request Forgery (CWE‑918) allows the attacker to retrieve data from a protected Azure platform channel that is normally unreachable from the public internet, potentially exposing internal information or services that should be hidden.
Affected Systems
This flaw affects installations of Open WebUI prior to version 0.11.1. The fix was included in the 0.11.1 release. All instances running older versions are vulnerable.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered medium‑to‑high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires authentication to the application; an attacker can trigger outbound requests to Azure internal addresses by submitting a crafted request. Because the attacker cannot execute arbitrary code, the impact is limited to potential data exposure and network reconnaissance. However, the ability to reach Azure internal services may aid in further attacks if additional credentials or lateral movement capabilities are obtained.
OpenCVE Enrichment