Skip to content

[GHSA-2823-wfgm-j3hr] open-webui v0.5.16 is vulnerable to SSRF in routers...#8034

Open
Classic298 wants to merge 1 commit into
Classic298/advisory-improvement-8034from
Classic298-GHSA-2823-wfgm-j3hr
Open

[GHSA-2823-wfgm-j3hr] open-webui v0.5.16 is vulnerable to SSRF in routers...#8034
Classic298 wants to merge 1 commit into
Classic298/advisory-improvement-8034from
Classic298-GHSA-2823-wfgm-j3hr

Conversation

@Classic298

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • References
  • Summary

Comments
Vendor (Open WebUI maintainer) request to withdraw or mark this advisory as disputed. The cited endpoint (routers/ollama.py:verify_connection) is admin-only — reachable only by an administrator verifying a model-server URL they themselves configured. The "attacker" is the admin using their own settings field. Out of scope per our published security policy (Rule 9, Admin Actions). We were not contacted before publication (originated from a personal markdown file in an unrelated repo, submitted directly to MITRE). Full vendor disposition: https://docs.openwebui.com/security/vendor-dispositions/cve-2025-29446/

Copilot stopped work on behalf of Classic298 due to an error June 12, 2026 22:51
@github-actions github-actions Bot changed the base branch from main to Classic298/advisory-improvement-8034 June 12, 2026 22:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant