Directory Traversal Vulnerability in Open WebUI by Open WebUI
CVE-2026-44565

8.1HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44565?

Open WebUI, an offline artificial intelligence platform, contains a vulnerability where uploaded audio file names are derived from the original HTTP request. This lack of validation and sanitization enables users to manipulate file paths, allowing the upload of files outside the designated directory, potentially exposing sensitive filesystem areas. This issue has been addressed in version 0.6.10, which reinforces proper file handling and security measures.

Affected Version(s)

open-webui < 0.6.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.