Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
GHSA-m8f9-9whg-f4xr · CVE-2026-45315
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
The audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/transcriptions/