
CVE-2026-45347 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.11, there is a blind server side request forgery (SSRF… https://www.cve.org/CVERecord?id=CVE-2026-45347
Post summary
The post announces CVE-2026-45347 affecting Open WebUI, detailing a blind SSRF vulnerability that existed before version 0.5.11, implying that the issue is fixed in that release. No PoC, exploit code, or evidence of active exploitation is provided.
