CVE-2024-7049
- EPSS 0.06%
- Veröffentlicht 10.10.2024 08:15:03
- Zuletzt bearbeitet 17.10.2024 14:22:44
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval process.
CVE-2024-7048
- EPSS 0.14%
- Veröffentlicht 10.10.2024 02:15:03
- Zuletzt bearbeitet 15.10.2025 13:15:51
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a ...
CVE-2024-7041
- EPSS 0.15%
- Veröffentlicht 09.10.2024 20:15:09
- Zuletzt bearbeitet 15.10.2025 13:15:51
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allo...
CVE-2024-7037
- EPSS 2.28%
- Veröffentlicht 09.10.2024 20:15:09
- Zuletzt bearbeitet 29.07.2025 18:47:38
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete...
CVE-2024-7038
- EPSS 0.21%
- Veröffentlicht 09.10.2024 19:15:14
- Zuletzt bearbeitet 03.11.2024 17:15:15
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides...
CVE-2024-6707
- EPSS 0.2%
- Veröffentlicht 07.08.2024 23:15:41
- Zuletzt bearbeitet 21.11.2024 09:50:09
Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.
CVE-2024-6706
- EPSS 0.19%
- Veröffentlicht 07.08.2024 23:15:41
- Zuletzt bearbeitet 21.11.2024 09:50:09
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
CVE-2024-30256
- EPSS 0.31%
- Veröffentlicht 16.04.2024 15:15:36
- Zuletzt bearbeitet 30.06.2025 14:30:00
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.