CVE-2026-54008
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.5 / 10
Vulnerability Description
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
pip
Product
open-webui
Discussion (0)
Add Comment
No comments yet. Be the first!