All vulnerabilities

GHSA-226F-F24G-524W

pip · open-webui

Summary

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

References