The flaw is in the shared backend/open_webui/retrieval/web/utils.py component used by server-side web fetches. The earlier check used Python's globally routable address classification as a proxy for whether a destination was external. Those questions are not equivalent: some special-purpose ranges are classified as globally routable even though they can identify internal or platform-specific endpoints.
A user-controlled URL reaches POST /api/v1/retrieval/process/web for RAG URL ingestion or POST /api/v1/retrieval/process/web/search for web search. Both paths require an authenticated, verified account, but no administrator role or special workspace permission. If the destination passes validation, Open WebUI makes the request from the server and returns the response body through the API, with the fetched content also entering the RAG context.
The advisory states that the vulnerable code ships in every build and is not limited to an optional component. The Azure platform channel at 168.63.129.16 is a concrete example because it can be reached from Azure virtual machines even though the library classifies the address as global. The exact internal data available depends on deployment routing and the permissions of the reachable endpoint; the available evidence does not establish the full set of accessible content.