openai is vulnerable to Path Traversal
59
Medium Risk
The Azure OpenAI client builds the deployment request path from the caller supplied deployment or model name without normalizing path segments first. A name containing ../ sequences escapes the intended /deployments/ segment and reaches a different Azure resource path than intended. The fix normalizes the deployment name before it is inserted into the request path.
You are affected if you are using a version that falls within the vulnerable range and you use the Azure OpenAI integration with a deployment or model name that is not fully controlled by you.
openai is vulnerable to Path Traversal in versions 4.41.0 - 7.4.0.
Upgrade the openai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.