Intel

AIKIDO-2026-842079

openai is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

59

Medium Risk

This Affects:

JSopenai
4.41.0 - 7.4.0
Fixed in 7.5.0
Are you affected? Scan for Free

TL;DR

The Azure OpenAI client builds the deployment request path from the caller supplied deployment or model name without normalizing path segments first. A name containing ../ sequences escapes the intended /deployments/ segment and reaches a different Azure resource path than intended. The fix normalizes the deployment name before it is inserted into the request path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the Azure OpenAI integration with a deployment or model name that is not fully controlled by you.

Background info

openai is vulnerable to Path Traversal in versions 4.41.0 - 7.4.0.

How to fix this

Upgrade the openai library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform