Executive brief
Open WebUI is a self-hosted interface for running artificial intelligence models offline. A security flaw allows logged-in users to access files in folders they shouldn't be able to see, such as backup or model storage directories. This could lead to the exposure of sensitive configuration data or internal system files if they are stored in specifically named sibling folders.
Technical details
A path traversal vulnerability exists in the `serve_cache_file()` function within `open_webui/main.py`. The application attempts to prevent traversal by checking if the resolved `file_path` starts with the `CACHE_DIR` path using `startswith()`. However, because it fails to append a trailing path separator (e.g., `/`) to the prefix, an attacker can use `../` to reach sibling directories that begin with the same string (e.g., `cache_backup` or `cache_models`). While deep traversal to arbitrary system files like `/etc/passwd` is blocked, access to these sibling directories is possible for any authenticated user. The issue is fixed in version 0.9.6 by ensuring the containment check includes the path separator.
Affected products
- open-webui open-webui < 0.9.6
Timeline
- 2026-06-11: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: NVD publication date