CVE-2026-34225: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that all...

Added to the CISA Known Exploited Vulnerabilities catalog on 14 Apr 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 4.3.

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allows editing an image via a prompt. The affected function performs a GET request to a user-provided U...

Required action: Review and patch if applicable to your AI infrastructure.