In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Wed, 15 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Tue, 29 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| CPEs | cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| Metrics |
cvssV3_1
|
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| CPEs | cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-webui
Open-webui open-webui |
|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models. | |
| Title | IDOR in open-webui/open-webui | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-10T01:22:16.902Z
Updated: 2025-10-15T12:49:49.363Z
Reserved: 2024-07-23T19:08:19.449Z
Link: CVE-2024-7048
Updated: 2024-10-10T14:48:50.628Z
Status : Modified
Published: 2024-10-10T02:15:03.113
Modified: 2025-10-15T13:15:51.940
Link: CVE-2024-7048
No data.