VYPR

PyPI package

open-webui

pkg:pypi/open-webui

Vulnerabilities (36)

  • CVE-2024-7053Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7046Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7045Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7044HigMar 20, 2025
    affected <= 0.3.8

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the v

  • CVE-2024-7043HigMar 20, 2025
    affected <= 0.3.8

    An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/files/ interface to retrieve in

  • CVE-2024-7039Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7036Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7035MedMar 20, 2025
    affected <= 0.3.8

    In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive

  • CVE-2024-7034Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7033Mar 20, 2025
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-12537Mar 20, 2025
    affected <= 0.3.32

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-12534Mar 20, 2025
    affected <= 0.3.32

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7041MedOct 9, 2024
    affected <= 0.3.8

    An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other u

  • CVE-2024-7037Oct 9, 2024
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7038Oct 9, 2024
    affected <= 0.3.8

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-6706MedAug 7, 2024
    affected <= 0.1.105

    Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Page 2 of 2