Open WebUI Path Traversal Vulnerability Leading to Arbitrary File Upload and Deletion

Vulnerability

A path traversal vulnerability allowing arbitrary file upload and deletion has been identified in Open WebUI versions prior to 0.6.10. The issue arises because uploaded audio files are sent to a static directory without proper validation or sanitization of the file names. This flaw enables users to traverse out of the designated upload directory and overwrite or delete files anywhere on the server's filesystem, depending on the permissions of the user running the web server.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads to locations outside the intended upload directory, with the potential to overwrite existing files or delete files, depending on the uploaded file's path.

Reproduction

To reproduce this vulnerability, upload a file through the Open WebUI HTTP interface using a valid user session. The file name can be crafted to include dot-segments that exploit the path traversal vulnerability, allowing the file to be uploaded to an arbitrary location on the server. After the file is uploaded, it will be deleted by the application, demonstrating the vulnerability's impact.

Remediation

Users are advised to update to Open WebUI version 0.6.10 or later, where this vulnerability has been fixed.

Added: May 15, 2026, 10:41 PM
Updated: May 15, 2026, 10:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
4.6
remediation
7.7
relevance
8.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.