Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2941 | In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete system files, potentially leading to remote code execution. |
Github GHSA |
GHSA-54f4-v6v9-9q82 | open-webui allows writing and deleting arbitrary files |
Tue, 29 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openwebui
Openwebui open Webui |
|
| CPEs | cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Openwebui
Openwebui open Webui |
|
| Metrics |
cvssV3_1
|
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-webui
Open-webui open-webui |
|
| CPEs | cpe:2.3:a:open-webui:open-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-webui
Open-webui open-webui |
|
| Metrics |
ssvc
|
Wed, 09 Oct 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability allows attackers to overwrite and delete system files, potentially leading to remote code execution. | |
| Title | Arbitrary File Write/Delete Leading to RCE in open-webui/open-webui | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-10-10T14:57:57.866Z
Reserved: 2024-07-23T17:48:28.192Z
Link: CVE-2024-7037
Updated: 2024-10-10T14:57:53.344Z
Status : Analyzed
Published: 2024-10-09T20:15:09.477
Modified: 2025-07-29T18:47:38.720
Link: CVE-2024-7037
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA