THREAT OPS › Threat News › [GHSA] GHSA-w2rx-84hp-gg95 (high) — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
[GHSA] GHSA-w2rx-84hp-gg95 (high) — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
GHSA-w2rx-84hp-gg95 Severity: high CVE: CVE-2026-70479
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
## Summary With the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-70479cve
- http://169.254.169.254/latest/meta-data/`url
Original source: https://github.com/advisories/GHSA-w2rx-84hp-gg95