CVE-2026-87996 | Open WebUI up to 0.11.0 SafePlaywrightURLLoader utils.py Hostname server-side request forgery

SecurityVulns

A vulnerability described as problematic has been identified in Open WebUI up to 0.11.0. Affected by this vulnerability is an unknown functionality of the file backend/open_webui/retrieval/web/utils.py of the component SafePlaywrightURLLoader. Executing a manipulation of the argument Hostname can lead to server-side request forgery.

This vulnerability is handled as CVE-2026-87996. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More