THREAT OPS › Threat News › [GHSA] GHSA-4v28-j6q3-5m4r (high) — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
[GHSA] GHSA-4v28-j6q3-5m4r (high) — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
GHSA-4v28-j6q3-5m4r Severity: high CVE: CVE-2026-87996
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
## Summary With the Playwright web loader enabled, Open WebUI checks the address behind a user-submitted URL before allowing the request, then handed the request to the browser to perform. The browser resolved the hostname a second time, on its own, and th
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-87996cve
Original source: https://github.com/advisories/GHSA-4v28-j6q3-5m4r