THREAT OPS › Threat News › [GHSA] GHSA-8x5v-cpv7-8jjp (high) — Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
[GHSA] GHSA-8x5v-cpv7-8jjp (high) — Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
GHSA-8x5v-cpv7-8jjp Severity: high CVE: CVE-2026-70485
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
## Summary
Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-70485cve
- http://169.254.169.254/latest/meta-data/url
- http://127.0.0.1/url
- http://metadata.google.internal/url
- 8.8.8.8ipv4
Original source: https://github.com/advisories/GHSA-8x5v-cpv7-8jjp