THREAT OPS › Threat News › [GHSA] GHSA-rffm-9q57-q649 (medium) — Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
[GHSA] GHSA-rffm-9q57-q649 (medium) — Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
GHSA-rffm-9q57-q649 Severity: medium CVE: CVE-2026-70480
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
## Summary Open WebUI renders `vega` and `vega-lite` fenced code blocks in chat content by building a Vega view in the viewer's browser without a restricted resource loader. Any user who can place such a block where another user will s
Indicators of compromise
- CVE-2026-70480cve
- https://vega.github.io/schema/vega-lite/v5.jsonurl
- http://attacker.example/probe?a=1url
Original source: https://github.com/advisories/GHSA-rffm-9q57-q649