Medium severity6.5NVD Advisory· Published Oct 9, 2024· Updated Jun 17, 2026
CVE-2024-7041
CVE-2024-7041
Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint http://0.0.0.0:3000/api/v1/memories/{id}/update, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
open-webuiPyPI | <= 0.3.8 | — |
Affected products
3cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/6855227f-1237-47b8-8d37-29aad7ddec3anvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xcvc-5hgv-phqgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-7041ghsaADVISORY
- github.com/open-webui/open-webui/blob/main/backend/apps/webui/routers/memories.pyghsaWEB
News mentions
0No linked articles in our index yet.