Skip to content
archiveexploit · 10 Sep 2026 · 15:10 UTC

GHSA-4v28-j6q3-5m4r: Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

EXPLCVE-2026-87996source · GTH
HIGHHigh-risk vulnerability — CVSS 7.7

last 60 dispatches · spectrum

## Summary With the Playwright web loader enabled, Open WebUI checks the address behind a user-submitted URL before allowing the request, then handed the request to the browser to perform. The browser resolved the hostname a second time, on its own, and that answer was never checked. An attacker who controls the authoritative DNS for a hostname they submit can answer the first lookup with a public address and the second with an internal one, so the browser connects to an address the check exists to block. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected