CVE-2026-5803 Details
Description
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API Proxy Endpoint. Performing a manipulation of the argument Query results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is named 54f8f50f43af97c334a881af7b021e84b5b8310f. It is suggested to install a patch to address this issue.
A server-side request forgery (SSRF) vulnerability has been identified in bigsk1 openai-realtime-ui, specifically in the API Proxy Endpoint within the server.js file, prior to commit 188ccde27fdf3d8fab8da81f3893468f53b2797c. The vulnerability arises because the /api/proxy endpoint accepts a user-supplied URL query parameter and forwards it to the fetch function without proper validation or allowlisting. This flaw can be exploited remotely, allowing attackers to make arbitrary outbound requests from the server. Such requests could access internal services, cloud metadata endpoints, or other restricted resources, potentially leading to unauthorized information disclosure and further compromise, depending on the internal environment.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 8, 2026CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bigsk1/openai-realtime-ui/ | [email protected] | ProductSource CodeVendor |
| https://github.com/bigsk1/openai-realtime-ui/commit/54f8f50f43af97c334a881af7b021e84b5b8310f | [email protected] | Source CodeVendor |
| https://github.com/bigsk1/openai-realtime-ui/issues/1 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/bigsk1/openai-realtime-ui/pull/2 | [email protected] | Issue TrackingVendor |
| https://github.com/BruceJqs/public_exp/issues/3 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/submit/786984 | [email protected] | Technical Description |
| https://vuldb.com/vuln/356242 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/356242/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bigsk1 openai-realtime-ui | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 8, 2026 | New CVE Received | [email protected] |
Volerion