A AegiFlow
LOWCVSS 2.0EPSS 0.3%

CVE-2024-7038

Withdrawn Advisory: open-webui allows enumeration of file names and traversal of directories by observing the error messages

Published
2024-10-09
Modified
2026-09-02
EPSS percentile
27%
Aliases
GHSA-mq92-jr35-ffpc
Sources
github-advisory

Summary

### Withdrawn Advisory This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references. ### Original Description An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides different error messages based on the existence and configuration of the file. This behavior allows an attacker to enumerate file names and traverse directories by observing the error messages, leading to potential exposure of sensitive information.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.