Executive brief
h2oGPT is an open-source generative AI platform. A security flaw in its file management system allows unauthorized individuals to bypass security checks and access the underlying server's files. An attacker could use this to steal sensitive data, delete critical system files, or take full control of the server by uploading malicious code.
Technical details
A path traversal vulnerability exists in the `get_user_dir` function within `openai_server/backend_utils.py`. The application uses the bearer token from the Authorization header unsanitized as a path component via `os.path.join`. Because the default API key configuration is set to 'EMPTY', authentication is bypassed, allowing unauthenticated attackers to inject traversal sequences (e.g., `../`) into the bearer token. This enables arbitrary file read, write, and delete operations via the `/v1/files` endpoints. Attackers can achieve remote code execution by overwriting application files or startup hooks. The vendor repository was archived in February 2026, and no official patch is currently available; users should manually configure a strong API key to mitigate the risk.
Affected products
- h2oai h2oGPT through 0.2.1
Timeline
- 2026-02-26: other: Project archived by owner
- 2026-07-23: disclosed: Vulnerability disclosed by VulnCheck
- 2026-07-23: advisory