PT-2026-56895 · Unknown · Open-Webui

CVE-2026-59221

·

Published

2026-06-16

·

Updated

2026-08-04

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions 0.9.6 through 0.9.9
Description The sanitize proxy path function in backend/open webui/routers/terminals.py fails to properly normalize proxy paths by decoding them only eight times. This allows a nine-times percent-encoded ../ traversal value to bypass normalization checks and be decoded by the upstream terminal server, potentially leading to path traversal.
Recommendations Update to version 0.10.0.

Exploit

Fix

DoS

SSRF

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09568
CVE-2026-59221
GHSA-FRVJ-C5QP-XJ4W
PYSEC-2026-3597

Affected Products

Open-Webui