PT-2026-31447 · Bigsk1 · Openai-Realtime-Ui

Brucejin

·

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-5803

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions bigsk1 openai-realtime-ui versions up to 188ccde27fdf3d8fab8da81f3893468f53b2797c
Description A security flaw exists in bigsk1 openai-realtime-ui. The issue is located in an unknown function within the server.js file of the API Proxy Endpoint component. Manipulation of the Query argument can lead to server-side request forgery (SSRF). This attack can be initiated remotely. The exploit is publicly available.
Recommendations Install patch 54f8f50f43af97c334a881af7b021e84b5b8310f to address this issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-5803

Affected Products

Openai-Realtime-Ui