THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w2rx-84hp-gg95 (high) — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

[GHSA] GHSA-w2rx-84hp-gg95 (high) — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

highgithub_advisoriesPublished 2026-08-04

GHSA-w2rx-84hp-gg95 Severity: high CVE: CVE-2026-70479

Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

## Summary With the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w2rx-84hp-gg95