CVE-2024-7045
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:10:18
- Zuletzt bearbeitet 15.10.2025 13:15:51
In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompts. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/pr...
CVE-2024-7035
- EPSS 0.04%
- Veröffentlicht 20.03.2025 10:10:03
- Zuletzt bearbeitet 29.07.2025 18:06:09
In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can uni...
CVE-2024-7036
- EPSS 0.49%
- Veröffentlicht 20.03.2025 10:09:57
- Zuletzt bearbeitet 18.07.2025 19:54:28
A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user...
CVE-2024-7033
- EPSS 1.16%
- Veröffentlicht 20.03.2025 10:09:54
- Zuletzt bearbeitet 29.07.2025 18:07:55
In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write...
CVE-2024-7040
- EPSS 0.11%
- Veröffentlicht 20.03.2025 10:09:45
- Zuletzt bearbeitet 15.10.2025 13:15:51
In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is pos...
CVE-2024-7046
- EPSS 0.06%
- Veröffentlicht 20.03.2025 10:09:38
- Zuletzt bearbeitet 15.10.2025 13:15:51
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admi...
CVE-2024-12537
- EPSS 0.77%
- Veröffentlicht 20.03.2025 10:09:10
- Zuletzt bearbeitet 04.04.2025 09:15:15
In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of c...
CVE-2024-9840
- EPSS 0.09%
- Veröffentlicht 20.03.2025 10:09:04
- Zuletzt bearbeitet 15.04.2025 16:15:47
Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-53981. Notes: All CVE users should reference CVE-2024-53981 instead of this CVE Record. All references and descriptions in this candidate ...
CVE-2024-7959
- EPSS 0.36%
- Veröffentlicht 20.03.2025 10:09:00
- Zuletzt bearbeitet 21.07.2025 20:06:27
The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and...
CVE-2024-7990
- EPSS 0.16%
- Veröffentlicht 20.03.2025 10:08:55
- Zuletzt bearbeitet 21.07.2025 20:07:26
A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in cha...