CVE-2026-44566Disclosure(openwebui / open_webui)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openwebui open_webui systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission. This vulnerability is fixed in 0.1.124.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_webui

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
open_webui

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-16: 2Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-16: 105-16
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44566 Path Traversal in Open WebUI Prior to 0.1.124 via Unsanitized File Upload Names https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44566

    Post summary

    A path traversal flaw was reported in Open WebUI prior to version 0.1.124, triggered by unsanitized file upload names.

    0000078
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44566 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the … https://www.cve.org/CVERecord?id=CVE-2026-44566

    Post summary

    The excerpt refers to CVE-2026-44566, indicating that a file‑attachment issue existed before Open WebUI version 0.1.124 and that this update likely mitigates the vulnerability.

    00000170
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenwebuiopen_webui---

Explore more