An authenticated attacker can change the destination reached by Open WebUI server-side fetches, bypassing the intended protection provided by the excluded-host list and part of the private-address control. Depending on the client and fetch path, the technical result may include reading content from an excluded public host or placing content from internal resources into responses, collections, or model input.
The flaw can affect resources outside the scope of the URL initially submitted by the user, but it requires an authenticated account and a configuration that permits redirect following. The record provides no evidence that the issue enables data modification, code execution, or denial of service. The amount of data exposed depends on the server's network access, the client used, and proxy configuration.