PT-2026-30677 · Whisper+1 · Whisperx+1

·

CVE-2026-34981

·

Published

2026-04-06

·

Updated

2026-04-27

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions whisperX versions 0.3.1 through 0.5.0
Description The whisperX API, a tool for enhancing and analyzing audio content, has a flaw in the FileService.download from url() function within app/services/file service.py. This function uses requests.get(url) without proper URL validation. The file extension check is performed after the HTTP request, allowing bypass by appending '.mp3' to internal URLs. The /speech-to-text-url endpoint is accessible without authentication.
Recommendations Update to version 0.6.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34981
GHSA-6RC7-R867-C635

Affected Products

Requests
Whisperx