CVE-2026-44566
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedOpen WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web server has permission. This vulnerability is fixed in 0.1.124.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceOpen WebUI before 0.1.124 fails to validate or sanitize filenames during file upload, allowing attackers to include dot-segments (../) in filenames to traverse directories and write files to arbitrary filesystem locations accessible to the web server process.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 0.1.124CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Open WebUI installation and versionLocate the Open WebUI installation directory or check the running container/application version. Common methods: check Docker image tag, look for version file in installation directory, or query the application API endpoint for version information.Affected if The installed version is older than 0.1.124 (e.g., 0.1.123, 0.1.122, etc.)
-
Verify file upload functionality is accessibleCheck if the file upload endpoint exists and is accessible to users. This is typically a POST endpoint for uploading files (often under /upload or similar path). Review the application routes or web server configuration to confirm upload endpoints are enabled.Affected if File upload endpoints are enabled and accessible to untrusted users
-
Inspect uploaded file storage locationReview the web server or application configuration to determine where uploaded files are stored on the filesystem. Check for any path validation logic in the upload handler.Affected if Uploaded files are stored in a location accessible beyond the intended upload directory (e.g., the web root, data directory, or system directories)
-
Review upload handler configurationExamine the web server or proxy configuration (e.g., nginx, Apache) for any filename sanitization rules or restrictions on upload requests. Check if the application has middleware or validation logic for uploaded filenames.Affected if No filename validation or traversal prevention is configured in the upload handler
You are affected if Open WebUI version is below 0.1.124 AND file upload functionality is accessible to users without additional validation of filenames for path traversal characters.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped0.1.124
Upgrade to Open WebUI version 0.1.124 or later. If unable to upgrade immediately, implement web server-level restrictions on uploaded filename characters and disable directory traversal in the upload handler.
Open WebUI version 0.1.124
- 1. Backup your current Open WebUI installation and any important data
- 2. Check your current Open WebUI version to confirm it is below 0.1.124
- 3. For Docker deployments: Pull the latest image tag or specifically the 0.1.124 tag (e.g., docker pull openwebui/open-webui:main or open-webui/open-webui:v0.1.124)
- 4. Stop the existing container
- 5. Remove the old container or redeploy with the new image
- 6. Start the container with the updated image
- 7. Verify the upgrade was successful by checking the version in the UI or via API
- 8. Test file upload functionality to confirm the path traversal fix is working
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation4.0 h
- Testing3.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,088.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2026-44566 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2026-44566 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data