Skip to content

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)

High severity GitHub Reviewed Published May 9, 2026 in open-webui/open-webui • Updated May 14, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts