Improper File Handling in Open WebUI Affects Audio Transcription Endpoint
CVE-2026-45315
8.7HIGH
What is CVE-2026-45315?
Open WebUI, a self-hosted artificial intelligence platform, has a vulnerability in its audio transcription upload feature. Prior to version 0.9.3, this endpoint incorrectly handles file extensions provided in user uploads. A malicious actor can craft a polyglot file, such as pwn.html, disguising it as a WAV file. When another verified user accesses the associated URL, the platform responds with 'text/html' content, allowing any embedded scripts to execute within the user's session. This poses a significant risk as the scripts run in the context of the Open WebUI origin, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
open-webui < 0.9.3
