Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-65958


Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to access cloud metadata endpoints (AWS/GCP/Azure), scan internal networks, access internal services behind firewalls, and exfiltrate sensitive information. No special permissions beyond basic authentication are required. This vulnerability is fixed in 0.6.37.


Published

2025-12-04T20:16:19.973

Last Modified

2025-12-10T15:18:38.043

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openwebui open_webui < 0.6.37 Yes

References