CVE-2026-70479High· 7.7▾ TwilightOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied by an authenticated user can use JavaScript to reach blocked internal addresses, and returned DOM can include data read from those addresses in web-search or RAG output. This issue is fixed in 0.11.0.
open_webui >= 0.9.6, < 0.11.0Upgrade past the affected range:
open_webui 0.11.0Affected packages:
open-webui >= 0.9.6, < 0.11.0Patched in:
open-webui 0.11.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70480Medium· 4.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70485High· 7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-54020Medium· 6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-87996High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70489Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2026-70491Medium· 6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform