<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:42:47.602332+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-45315</id>
    <title>CVE-2026-45315 — Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions</title>
    <updated>2026-10-03T17:42:47.604801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> open-webui</p>
<p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/transcriptions/.. The /cache/{path} route serves these files via FileResponse, which sets Content-Type from the on-disk extension and emits no Content-Disposition. A verified user with the default-on chat.stt permission can upload a polyglot WAV+HTML file named pwn.html and trick any other user into opening the resulting URL — the response comes back as text/html and any embedded &lt;script&gt; runs in the Open WebUI origin. This vulnerability is fixed in 0.9.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-45315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8f9-9whg-f4xr</id>
    <title>GHSA-m8f9-9whg-f4xr — Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions</title>
    <updated>2026-10-03T17:42:47.604864+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: open-webui</p>
<p>## Summary</p>
<p>The audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/transcriptions/&lt;uuid&gt;.&lt;ext&gt;. The /cache/{path} route serves these files via FileResponse, which sets Content-Type from the on-disk extension and emits no Content-Disposition. A verified user with the default-on chat.stt permission can upload a polyglot WAV+HTML file named pwn.html and trick any other user into opening the resulting URL — the response comes back as text/html and any embedded &lt;script&gt; runs in the Open WebUI origin.</p>
<p>## Details
  Verified on main @ 8dae237a (v0.9.2):                                                                                                       
  - backend/open_webui/routers/audio.py:1244-1249 — ext = safe_name.rsplit('.', 1)[-1] from user-supplied filename, then filename = f'{id}.{ext}'. No      
  allowlist, no cross-check against file.content_type.                                                                                                   
  - backend/open_webui/main.py:2768-2779 — /cache/{path:path} returns FileResponse(file_path). Starlette derives Content-Type from the filename extension  
  and sets no Content-Disposition.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8f9-9whg-f4xr"/>
  </entry>
</feed>
