<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 15:23:06 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09526</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09526</link>
      <description>bdu:2026-09526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09526</guid>
    </item>
    <item>
      <title>EUVD-2026-319381</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319381</link>
      <description>EUVD-2026-319381</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319381</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44566</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44566</link>
      <description>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission. This vulnerability is fixed in 0.1.124.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission. This vulnerability is fixed in 0.1.124.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44566</guid>
    </item>
    <item>
      <title>GHSA-9pgh-j74g-qj6m — Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9pgh-j74g-qj6m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# **CONFIDENTIAL**&lt;/p&gt;
&lt;p&gt;# KL-CAN-2024-002&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| # | Field | Value |
|---|-------|-------|
| 1 | **Discoverer** | Jaggar Henry &amp;amp; Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **Affected Vendor** | Open WebUI |
| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |
| 7 | **Affected Version(s)** | 0.1.105 |
| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |
| 9 | **Vector** | HTTP web interface |
| 10 | **CWE** | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), CWE-434: Unrestricted Upload of File with Dangerous Type |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 4. High-level Summary&lt;/p&gt;
&lt;p&gt;Attacker controlled files can be uploaded to arbitrary locations on the web server&amp;#39;s filesystem by abusing a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 11. Technical Analysis&lt;/p&gt;
&lt;p&gt;When attaching files to a prompt by clicking the plus sign (+) on the left of the message input box when using the Open WebUI HTTP interface, the file is uploaded to a static upload directory.&lt;/p&gt;
&lt;p&gt;The name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission.&lt;/p&gt;
&lt;p&gt;This can be visualized by examining th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# **CONFIDENTIAL**&lt;/p&gt;
&lt;p&gt;# KL-CAN-2024-002&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| # | Field | Value |
|---|-------|-------|
| 1 | **Discoverer** | Jaggar Henry &amp;amp; Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **Affected Vendor** | Open WebUI |
| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |
| 7 | **Affected Version(s)** | 0.1.105 |
| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |
| 9 | **Vector** | HTTP web interface |
| 10 | **CWE** | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), CWE-434: Unrestricted Upload of File with Dangerous Type |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 4. High-level Summary&lt;/p&gt;
&lt;p&gt;Attacker controlled files can be uploaded to arbitrary locations on the web server&amp;#39;s filesystem by abusing a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 11. Technical Analysis&lt;/p&gt;
&lt;p&gt;When attaching files to a prompt by clicking the plus sign (+) on the left of the message input box when using the Open WebUI HTTP interface, the file is uploaded to a static upload directory.&lt;/p&gt;
&lt;p&gt;The name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission.&lt;/p&gt;
&lt;p&gt;This can be visualized by examining th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9pgh-j74g-qj6m</guid>
    </item>
    <item>
      <title>PYSEC-2026-2717 — Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2717</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# **CONFIDENTIAL**&lt;/p&gt;
&lt;p&gt;# KL-CAN-2024-002&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| # | Field | Value |
|---|-------|-------|
| 1 | **Discoverer** | Jaggar Henry &amp;amp; Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **Affected Vendor** | Open WebUI |
| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |
| 7 | **Affected Version(s)** | 0.1.105 |
| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |
| 9 | **Vector** | HTTP web interface |
| 10 | **CWE** | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), CWE-434: Unrestricted Upload of File with Dangerous Type |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 4. High-level Summary&lt;/p&gt;
&lt;p&gt;Attacker controlled files can be uploaded to arbitrary locations on the web server&amp;#39;s filesystem by abusing a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 11. Technical Analysis&lt;/p&gt;
&lt;p&gt;When attaching files to a prompt by clicking the plus sign (+) on the left of the message input box when using the Open WebUI HTTP interface, the file is uploaded to a static upload directory.&lt;/p&gt;
&lt;p&gt;The name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission.&lt;/p&gt;
&lt;p&gt;This can be visualized by examining th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: open-webui&lt;/p&gt;
&lt;p&gt;# **CONFIDENTIAL**&lt;/p&gt;
&lt;p&gt;# KL-CAN-2024-002&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;| # | Field | Value |
|---|-------|-------|
| 1 | **Discoverer** | Jaggar Henry &amp;amp; Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **Affected Vendor** | Open WebUI |
| 6 | **Affected Product(s)** | Open WebUI (Formerly Ollama WebUI) |
| 7 | **Affected Version(s)** | 0.1.105 |
| 8 | **Platform/OS** | Debian GNU/Linux 12 (bookworm) |
| 9 | **Vector** | HTTP web interface |
| 10 | **CWE** | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;), CWE-434: Unrestricted Upload of File with Dangerous Type |&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 4. High-level Summary&lt;/p&gt;
&lt;p&gt;Attacker controlled files can be uploaded to arbitrary locations on the web server&amp;#39;s filesystem by abusing a path traversal vulnerability.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 11. Technical Analysis&lt;/p&gt;
&lt;p&gt;When attaching files to a prompt by clicking the plus sign (+) on the left of the message input box when using the Open WebUI HTTP interface, the file is uploaded to a static upload directory.&lt;/p&gt;
&lt;p&gt;The name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission.&lt;/p&gt;
&lt;p&gt;This can be visualized by examining th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2717</guid>
    </item>
  </channel>
</rss>
