mirror of
https://github.com/open-webui/docs.git
synced 2026-07-21 01:55:22 -04:00
Merge branch 'main' into dev
This commit is contained in:
@@ -9,6 +9,7 @@ title: "CVE-2024-7033"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7033](https://www.cve.org/CVERecord?id=CVE-2024-7033) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1)) |
|
||||
| **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7033"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7034"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7034](https://www.cve.org/CVERecord?id=CVE-2024-7034) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613)) |
|
||||
| **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7034"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7038"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7038](https://www.cve.org/CVERecord?id=CVE-2024-7038) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2024-10-09 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/f42cf72a-8015-44a6-81a9-c6332ef05afc)) |
|
||||
| **Claimed Severity** | Low (CVSS 2.7, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7038"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2024-10-09 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7039"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7039](https://www.cve.org/CVERecord?id=CVE-2024-7039) |
|
||||
| **Vendor Disposition** | Rejected, out of scope; severity inflated |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc)) |
|
||||
| **Claimed Severity** | High (CVSS 8.3, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7039"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7040"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7040](https://www.cve.org/CVERecord?id=CVE-2024-7040) |
|
||||
| **Vendor Disposition** | Rejected, out of scope |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-10-15 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1)) |
|
||||
| **Claimed Severity** | Medium (CVSS 4.9, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) |
|
||||
@@ -18,7 +19,7 @@ title: "CVE-2024-7040"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is formally disputed. The dispute is open and being pursued through the CVE Program's process; the assessment below is Open WebUI's position in the meantime.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
@@ -28,8 +29,11 @@ This CVE is formally disputed. The dispute is open and being pursued through the
|
||||
| 2026-06-15 | Open WebUI files another dispute with the CVE Program; the Secretariat directs it to the issuing CNA (huntr / Protect AI), which owns the record. |
|
||||
| 2026-06-17 | Open WebUI contacts huntr / Protect AI directly. No response. |
|
||||
| 2026-07-02 | With the CNA non-responsive, Open WebUI escalates the dispute a third time, to the CVE Program's Root / Top-Level Root under the CVE Record Dispute Policy (v2.0.0). |
|
||||
| 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. |
|
||||
| 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. |
|
||||
| 2026-07-16 | huntr / Protect AI withdraws the record. |
|
||||
|
||||
As of 2026-07-02 the dispute remains open and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ title: "CVE-2024-7959"
|
||||
| :--- | :--- |
|
||||
| **CVE ID** | [CVE-2024-7959](https://www.cve.org/CVERecord?id=CVE-2024-7959) |
|
||||
| **Vendor Disposition** | Rejected, out of scope; severity inflated |
|
||||
| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** |
|
||||
| **Published** | 2025-03-20 |
|
||||
| **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/3c8bea0a-d678-4d67-bb9c-2b5b610a2193)) |
|
||||
| **Claimed Severity** | High (CVSS 7.7, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) |
|
||||
@@ -17,15 +18,16 @@ title: "CVE-2024-7959"
|
||||
|
||||
## Timeline
|
||||
|
||||
This CVE is disputed. The assessment below is Open WebUI's position.
|
||||
This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected.
|
||||
|
||||
| Date | Event |
|
||||
| :--- | :--- |
|
||||
| 2025-03-20 | huntr / Protect AI publishes the CVE. |
|
||||
| 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. |
|
||||
| 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. |
|
||||
| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. |
|
||||
|
||||
As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment.
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -49,10 +49,10 @@ For a full overview, see the [Security Policy](../security-policy).
|
||||
| [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 |
|
||||
| [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-12-18 |
|
||||
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 |
|
||||
| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-10-15 |
|
||||
| [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-04-21 |
|
||||
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 |
|
||||
| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | In progress | 2025-03-20 |
|
||||
| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2024-10-09 |
|
||||
| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | <span className="badge badge--success">CNA REJECTED</span> | 2025-03-20 |
|
||||
|
||||
Reference in New Issue
Block a user