mirror of
https://github.com/open-webui/docs.git
synced 2026-07-21 01:55:22 -04:00
Record CNA withdrawal of six disputed CVEs
huntr / Protect AI accepted Open WebUI's disputes and withdrew CVE-2024-7040, -7959, -7039, -7038, -7034 and -7033. All six are now in the REJECTED state on cve.org, which propagates to NVD and downstream feeds. Mark them as CNA REJECTED in the Official Resolution column, add an Official Resolution row and the withdrawal to the timeline on each disposition page, and replace the dispute-pending wording with the resolved outcome. CVE-2024-7040 also gains the Root's routing of the dispute to the CNA under Program Rule 4.1 and the CNA's acceptance. The three ZDI records remain in progress and are unchanged.
This commit is contained in:
@@ -9,6 +9,7 @@ title: "CVE-2024-7033"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7033](https://www.cve.org/CVERecord?id=CVE-2024-7033) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1)) |
|
||||
| **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7033"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7034"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7034](https://www.cve.org/CVERecord?id=CVE-2024-7034) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613)) |
|
||||
| **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7034"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7038"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7038](https://www.cve.org/CVERecord?id=CVE-2024-7038) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2024-10-09 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/f42cf72a-8015-44a6-81a9-c6332ef05afc)) |
|
||||
| **Claimed Severity** | Low (CVSS 2.7, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7038"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2024-10-09 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7039"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7039](https://www.cve.org/CVERecord?id=CVE-2024-7039) |
|
||||
| **Vendor Disposition** | Rejected, out of scope; severity inflated |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc)) |
|
||||
| **Claimed Severity** | High (CVSS 8.3, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7039"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7040"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7040](https://www.cve.org/CVERecord?id=CVE-2024-7040) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-10-15 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1)) |
|
||||
| **Claimed Severity** | Medium (CVSS 4.9, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) |
|
||||
@@ -18,7 +19,7 @@ title: "CVE-2024-7040"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is formally disputed. The dispute is open and being pursued through the CVE Program's process; the assessment below is Open WebUI's position in the meantime.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
@@ -28,8 +29,11 @@ This CVE is formally disputed. The dispute is open and being pursued through the
|
||||
| 2026-06-15 | Open WebUI files another dispute with the CVE Program; the Secretariat directs it to the issuing CNA (huntr / Protect AI), which owns the record. |
|
||||
| 2026-06-17 | Open WebUI contacts huntr / Protect AI directly. No response. |
|
||||
| 2026-07-02 | With the CNA non-responsive, Open WebUI escalates the dispute a third time, to the CVE Program's Root / Top-Level Root under the CVE Record Dispute Policy (v2.0.0). |
|
||||
| 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. |
|
||||
| 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. |
|
||||
| 2026-07-16 | huntr / Protect AI withdraws the record. |
|
||||
|
||||
As of 2026-07-02 the dispute remains open and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7959"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7959](https://www.cve.org/CVERecord?id=CVE-2024-7959) |
|
||||
| **Vendor Disposition** | Rejected, out of scope; severity inflated |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/3c8bea0a-d678-4d67-bb9c-2b5b610a2193)) |
|
||||
| **Claimed Severity** | High (CVSS 7.7, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7959"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -49,10 +49,10 @@ For a full overview, see the [Security Policy](../security-policy).
|
||||
| [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-12-18 |
|
||||
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 |
|
||||
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-10-15 |
|
||||
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-04-21 |
|
||||
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 |
|
||||
| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2024-10-09 |
|
||||
| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
|
||||
Reference in New Issue
Block a user