From 387225eb8b3906909436004f84fff1b012e067d4 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Sun, 1 Mar 2026 20:44:49 +0100 Subject: [PATCH] fix: suppress internal path leakage in audio transcription errors (GHSA-vvxm-vxmr-624h) (#22108) - Use os.path.basename() for filename sanitization instead of fragile blocklist - Replace ERROR_MESSAGES.DEFAULT(e) with generic error message in both except blocks to prevent CWE-209 information disclosure - Server-side logging via log.exception(e) is preserved for debugging --- backend/open_webui/routers/audio.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/backend/open_webui/routers/audio.py b/backend/open_webui/routers/audio.py index a877d1e8d..315607832 100644 --- a/backend/open_webui/routers/audio.py +++ b/backend/open_webui/routers/audio.py @@ -1194,8 +1194,8 @@ def transcription( ) try: - ext = file.filename.split(".")[-1] if file.filename else "" - ext = ext.replace("/", "").replace("\\", "").replace("..", "") + safe_name = os.path.basename(file.filename) if file.filename else "" + ext = safe_name.rsplit(".", 1)[-1] if "." in safe_name else "" id = uuid.uuid4() @@ -1231,7 +1231,7 @@ def transcription( raise HTTPException( status_code=status.HTTP_400_BAD_REQUEST, - detail=ERROR_MESSAGES.DEFAULT(e), + detail="Transcription failed.", ) except Exception as e: @@ -1239,7 +1239,7 @@ def transcription( raise HTTPException( status_code=status.HTTP_400_BAD_REQUEST, - detail=ERROR_MESSAGES.DEFAULT(e), + detail="Transcription failed.", )