Improper File Handling in Open WebUI Affects Audio Transcription Endpoint
CVE-2026-45315

8.7HIGH

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-45315?

Open WebUI, a self-hosted artificial intelligence platform, has a vulnerability in its audio transcription upload feature. Prior to version 0.9.3, this endpoint incorrectly handles file extensions provided in user uploads. A malicious actor can craft a polyglot file, such as pwn.html, disguising it as a WAV file. When another verified user accesses the associated URL, the platform responds with 'text/html' content, allowing any embedded scripts to execute within the user's session. This poses a significant risk as the scripts run in the context of the Open WebUI origin, potentially leading to unauthorized actions or data exposure.

Affected Version(s)

open-webui < 0.9.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.