A AegiFlow
MEDIUMCVSS 4.9EPSS 0.6%

CVE-2024-7040

Withdrawn Advisory: Open WebUI Access Control

Published
2025-03-20
Modified
2026-09-02
EPSS percentile
43%
Aliases
GHSA-cfvq-fj53-j2c7
Sources
github-advisory

Summary

### Withdrawn Advisory This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references. ### Original Description In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, including those of other admin (owner) accounts.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.