diff --git a/docs/security/vendor-dispositions/cve-2024-7033.mdx b/docs/security/vendor-dispositions/cve-2024-7033.mdx index 1180a4be..f43962fc 100644 --- a/docs/security/vendor-dispositions/cve-2024-7033.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7033.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7033" | :--- | :--- | | **CVE ID** | [CVE-2024-7033](https://www.cve.org/CVERecord?id=CVE-2024-7033) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1)) | | **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) | @@ -17,15 +18,16 @@ title: "CVE-2024-7033" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7034.mdx b/docs/security/vendor-dispositions/cve-2024-7034.mdx index 490a83c5..47c76b83 100644 --- a/docs/security/vendor-dispositions/cve-2024-7034.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7034.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7034" | :--- | :--- | | **CVE ID** | [CVE-2024-7034](https://www.cve.org/CVERecord?id=CVE-2024-7034) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613)) | | **Claimed Severity** | Medium (CVSS 6.5, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) | @@ -17,15 +18,16 @@ title: "CVE-2024-7034" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7038.mdx b/docs/security/vendor-dispositions/cve-2024-7038.mdx index 2491b33c..bf50fd88 100644 --- a/docs/security/vendor-dispositions/cve-2024-7038.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7038.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7038" | :--- | :--- | | **CVE ID** | [CVE-2024-7038](https://www.cve.org/CVERecord?id=CVE-2024-7038) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2024-10-09 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/f42cf72a-8015-44a6-81a9-c6332ef05afc)) | | **Claimed Severity** | Low (CVSS 2.7, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) | @@ -17,15 +18,16 @@ title: "CVE-2024-7038" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2024-10-09 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7039.mdx b/docs/security/vendor-dispositions/cve-2024-7039.mdx index c8b87d3c..2276dd6f 100644 --- a/docs/security/vendor-dispositions/cve-2024-7039.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7039.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7039" | :--- | :--- | | **CVE ID** | [CVE-2024-7039](https://www.cve.org/CVERecord?id=CVE-2024-7039) | | **Vendor Disposition** | Rejected, out of scope; severity inflated | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc)) | | **Claimed Severity** | High (CVSS 8.3, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L) | @@ -17,15 +18,16 @@ title: "CVE-2024-7039" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7040.mdx b/docs/security/vendor-dispositions/cve-2024-7040.mdx index 6ddb8f35..94f545fe 100644 --- a/docs/security/vendor-dispositions/cve-2024-7040.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7040.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7040" | :--- | :--- | | **CVE ID** | [CVE-2024-7040](https://www.cve.org/CVERecord?id=CVE-2024-7040) | | **Vendor Disposition** | Rejected, out of scope | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-10-15 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1)) | | **Claimed Severity** | Medium (CVSS 4.9, CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) | @@ -18,7 +19,7 @@ title: "CVE-2024-7040" ## Timeline -This CVE is formally disputed. The dispute is open and being pursued through the CVE Program's process; the assessment below is Open WebUI's position in the meantime. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | @@ -28,8 +29,11 @@ This CVE is formally disputed. The dispute is open and being pursued through the | 2026-06-15 | Open WebUI files another dispute with the CVE Program; the Secretariat directs it to the issuing CNA (huntr / Protect AI), which owns the record. | | 2026-06-17 | Open WebUI contacts huntr / Protect AI directly. No response. | | 2026-07-02 | With the CNA non-responsive, Open WebUI escalates the dispute a third time, to the CVE Program's Root / Top-Level Root under the CVE Record Dispute Policy (v2.0.0). | +| 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. | +| 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. | +| 2026-07-16 | huntr / Protect AI withdraws the record. | -As of 2026-07-02 the dispute remains open and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/cve-2024-7959.mdx b/docs/security/vendor-dispositions/cve-2024-7959.mdx index ce602f11..08b71c42 100644 --- a/docs/security/vendor-dispositions/cve-2024-7959.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7959.mdx @@ -9,6 +9,7 @@ title: "CVE-2024-7959" | :--- | :--- | | **CVE ID** | [CVE-2024-7959](https://www.cve.org/CVERecord?id=CVE-2024-7959) | | **Vendor Disposition** | Rejected, out of scope; severity inflated | +| **Official Resolution** | Withdrawn by the issuing CNA on 2026-07-16; the record is **REJECTED** | | **Published** | 2025-03-20 | | **Issuing CNA** | huntr / Protect AI (from a [bounty report](https://huntr.com/bounties/3c8bea0a-d678-4d67-bb9c-2b5b610a2193)) | | **Claimed Severity** | High (CVSS 7.7, CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) | @@ -17,15 +18,16 @@ title: "CVE-2024-7959" ## Timeline -This CVE is disputed. The assessment below is Open WebUI's position. +This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessment below is the basis on which the record was rejected. | Date | Event | | :--- | :--- | | 2025-03-20 | huntr / Protect AI publishes the CVE. | | 2026-07-08 | Open WebUI publishes this disposition, rejecting the report as out of scope; severity inflated. | | 2026-07-08 | Open WebUI contacts huntr / Protect AI directly to dispute the record. | +| 2026-07-16 | huntr / Protect AI accepts the dispute and withdraws the record. | -As of 2026-07-08, the dispute has been raised with the issuing CNA (huntr / Protect AI) and the CVE record has not been amended. This disposition stands as Open WebUI's official assessment. +The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability. --- diff --git a/docs/security/vendor-dispositions/index.mdx b/docs/security/vendor-dispositions/index.mdx index 6aa30c4b..9067aa3e 100644 --- a/docs/security/vendor-dispositions/index.mdx +++ b/docs/security/vendor-dispositions/index.mdx @@ -49,10 +49,10 @@ For a full overview, see the [Security Policy](../security-policy). | [CVE-2026-0766](./cve-2026-0766) | load_tool_module_by_id Code Injection | Rejected | In progress | 2026-01-23 | | [CVE-2026-0767](./cve-2026-0767) | Cleartext Transmission of Credentials | Rejected | In progress | 2026-01-23 | | [CVE-2025-63391](./cve-2025-63391) | Authentication Bypass in /api/config | Rejected | CNA REJECTED | 2025-12-18 | -| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | In progress | 2025-10-15 | +| [CVE-2024-7040](./cve-2024-7040) | Cross-Admin Chat Access via user_id Parameter | Rejected | CNA REJECTED | 2025-10-15 | | [CVE-2025-29446](./cve-2025-29446) | SSRF in verify_connection | Rejected | CNA REJECTED | 2025-04-21 | -| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | In progress | 2024-10-09 | -| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | In progress | 2025-03-20 | -| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | In progress | 2025-03-20 | +| [CVE-2024-7033](./cve-2024-7033) | Path Traversal in Model Download | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7034](./cve-2024-7034) | Path Traversal in Model Upload | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7038](./cve-2024-7038) | Path Oracle in Embedding-Model Update | Rejected | CNA REJECTED | 2024-10-09 | +| [CVE-2024-7039](./cve-2024-7039) | Cross-Admin User Deletion | Rejected | CNA REJECTED | 2025-03-20 | +| [CVE-2024-7959](./cve-2024-7959) | SSRF via Admin-Configured OpenAI URL | Rejected | CNA REJECTED | 2025-03-20 |