From 23910c12a6547f7fa51399e55ed85ff78c69efdf Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Thu, 16 Jul 2026 19:30:01 +0200 Subject: [PATCH] Record CNA withdrawal of six disputed CVEs huntr / Protect AI accepted Open WebUI's disputes and withdrew CVE-2024-7040, -7959, -7039, -7038, -7034 and -7033. All six are now in the REJECTED state on cve.org, which propagates to NVD and downstream feeds. Mark them as CNA REJECTED in the Official Resolution column, add an Official Resolution row and the withdrawal to the timeline on each disposition page, and replace the dispute-pending wording with the resolved outcome. CVE-2024-7040 also gains the Root's routing of the dispute to the CNA under Program Rule 4.1 and the CNA's acceptance. The three ZDI records remain in progress and are unchanged. --- docs/security/vendor-dispositions/cve-2024-7033.mdx | 6 ++++-- docs/security/vendor-dispositions/cve-2024-7034.mdx | 6 ++++-- docs/security/vendor-dispositions/cve-2024-7038.mdx | 6 ++++-- docs/security/vendor-dispositions/cve-2024-7039.mdx | 6 ++++-- docs/security/vendor-dispositions/cve-2024-7040.mdx | 8 ++++++-- docs/security/vendor-dispositions/cve-2024-7959.mdx | 6 ++++-- docs/security/vendor-dispositions/index.mdx | 12 ++++++------ 7 files changed, 32 insertions(+), 18 deletions(-) diff --git a/docs/security/vendor-dispositions/cve-2024-7033.mdx b/docs/security/vendor-dispositions/cve-2024-7033.mdx index 1180a4be..f43962fc 100644 --- a/docs/security/vendor-dispositions/cve-2024-7033.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7033.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7033" | :--- | :--- | | **CVE ID** | [CVE-2024-7033](https://www.cve.org/CVERecord?id=CVE-2024-7033) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1)) | | **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) | @@ -17,15 +18,16 @@ title: "CVE-2024-7033" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7034.mdx b/docs/security/vendor-dispositions/cve-2024-7034.mdx index 490a83c5..47c76b83 100644 --- a/docs/security/vendor-dispositions/cve-2024-7034.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7034.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7034" | :--- | :--- | | **CVE ID** | [CVE-2024-7034](https://www.cve.org/CVERecord?id=CVE-2024-7034) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613)) | | **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) | @@ -17,15 +18,16 @@ title: "CVE-2024-7034" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7038.mdx b/docs/security/vendor-dispositions/cve-2024-7038.mdx index 2491b33c..bf50fd88 100644 --- a/docs/security/vendor-dispositions/cve-2024-7038.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7038.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7038" | :--- | :--- | | **CVE ID** | [CVE-2024-7038](https://www.cve.org/CVERecord?id=CVE-2024-7038) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2024-10-09 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/f42cf72a-8015-44a6-81a9-c6332ef05afc)) | | **Claimed Severity** | Low (CVSS 2.7, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) | @@ -17,15 +18,16 @@ title: "CVE-2024-7038" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2024-10-09 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7039.mdx b/docs/security/vendor-dispositions/cve-2024-7039.mdx index c8b87d3c..2276dd6f 100644 --- a/docs/security/vendor-dispositions/cve-2024-7039.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7039.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7039" | :--- | :--- | | **CVE ID** | [CVE-2024-7039](https://www.cve.org/CVERecord?id=CVE-2024-7039) | | **Vendor Disposition** | Rejected, out of scope; severity inflated | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc)) | | **Claimed Severity** | High (CVSS 8.3, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) | @@ -17,15 +18,16 @@ title: "CVE-2024-7039" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7040.mdx b/docs/security/vendor-dispositions/cve-2024-7040.mdx index 6ddb8f35..94f545fe 100644 --- a/docs/security/vendor-dispositions/cve-2024-7040.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7040.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7040" | :--- | :--- | | **CVE ID** | [CVE-2024-7040](https://www.cve.org/CVERecord?id=CVE-2024-7040) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-10-15 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1)) | | **Claimed Severity** | Medium (CVSS 4.9, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) | @@ -18,7 +19,7 @@ title: "CVE-2024-7040" ## Timeline -This CVE is formally disputed. The dispute is open and being pursued through the CVE Program's process; the assessment below is Open WebUI's position in the meantime. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | @@ -28,8 +29,11 @@ This CVE is formally disputed. The dispute is open and being pursued through the | 2026-06-15 | Open WebUI files another dispute with the CVE Program; the Secretariat directs it to the issuing CNA (huntr / Protect AI), which owns the record. | | 2026-06-17 | Open WebUI contacts huntr / Protect AI directly. No response. | | 2026-07-02 | With the CNA non-responsive, Open WebUI escalates the dispute a third time, to the CVE Program's Root / Top-Level Root under the CVE Record Dispute Policy (v2.0.0). | +| 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. | +| 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. | +| 2026-07-16 | huntr / Protect AI withdraws the record. | -As of 2026-07-02 the dispute remains open and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7959.mdx b/docs/security/vendor-dispositions/cve-2024-7959.mdx index ce602f11..08b71c42 100644 --- a/docs/security/vendor-dispositions/cve-2024-7959.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7959.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7959" | :--- | :--- | | **CVE ID** | [CVE-2024-7959](https://www.cve.org/CVERecord?id=CVE-2024-7959) | | **Vendor Disposition** | Rejected, out of scope; severity inflated | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/3c8bea0a-d678-4d67-bb9c-2b5b610a2193)) | | **Claimed Severity** | High (CVSS 7.7, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) | @@ -17,15 +18,16 @@ title: "CVE-2024-7959" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/index.mdx b/docs/security/vendor-dispositions/index.mdx index 6aa30c4b..9067aa3e 100644 --- a/docs/security/vendor-dispositions/index.mdx +++ b/docs/security/vendor-dispositions/index.mdx @@ -49,10 +49,10 @@ For a full overview, see the [Security Policy](../security-policy). | [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 | | [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 | | [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | CNA REJECTED | 2025-12-18 | -| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 | +| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | CNA REJECTED | 2025-10-15 | | [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | CNA REJECTED | 2025-04-21 | -| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 | -| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | In progress | 2025-03-20 | +| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | CNA REJECTED | 2024-10-09 | +| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | CNA REJECTED | 2025-03-20 |