VYPR
Medium severity5.4NVD Advisory· Published Oct 10, 2024· Updated Jun 17, 2026

CVE-2024-7048

CVE-2024-7048

Description

In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
    • (no CPE)range: =v0.3.8
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.