A AegiFlow
HIGHCVSS 7.7EPSS 24.5%

CVE-2024-7959

Withdrawn Advisory: Open WebUI has SSRF in /openai/models

Published
2025-03-20
Modified
2026-09-02
EPSS percentile
98%
Aliases
GHSA-x757-hv69-jr45
Sources
github-advisory

Summary

### Withdrawn Advisory This advisory has been withdrawn because it does not describe a valid vulnerability. This link is maintained to preserve external references. ### Original Description The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.