CVE-2024-7959 – open-webui
Package
Manager: pip
Name: open-webui
Vulnerable Version: >=0 <=0.3.8
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
EPSS: 0.00069 pctl0.2175
Details
Open WebUI has SSRF in /openai/models The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.
Metadata
Created: 2025-03-20T12:32:46Z
Modified: 2025-03-21T21:16:29Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json
CWE IDs: ["CWE-918"]
Alternative ID: GHSA-x757-hv69-jr45
Finding: F100
Auto approve: 1