Medium severity6.4NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026
CVE-2024-30256
CVE-2024-30256
Description
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openwebui:open_webui:*:*:*:*:*:*:*:*range: <0.1.117
- (no CPE)range: <0.1.117
- (no CPE)range: < 0.1.117
Patches
Vulnerability mechanics
References
2- securitylab.github.com/advisories/GHSL-2024-033_open-webuinvdExploitThird Party Advisory
- github.com/open-webui/open-webui/security/advisories/GHSA-39wr-r5vm-3jxjnvdVendor Advisory
News mentions
0No linked articles in our index yet.