CVE-2026-54018 | open-webui Open WebUI up to 0.9.5 Docker Container server-side request forgery (GHSA-jrfp-m64g-pcwv)
A vulnerability, which was classified as critical, was found in open-webui Open WebUI up to 0.9.5. This issue affects some unknown processing of the component Docker Container Handler. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-54018. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.