CVE-2024-7040

In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, including those of other admin (owner) accounts.
References
Link Resource
https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*

History

18 Jul 2025, 19:44

Type Values Removed Values Added
CPE cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*
References () https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1 - () https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1 - Exploit, Third Party Advisory
Summary
  • (es) En la versión v0.3.8 de open-webui/open-webui, existe una vulnerabilidad de control de acceso indebido. En la página de administración del frontend, los administradores solo pueden ver los chats de miembros no administradores. Sin embargo, modificando el parámetro user_id, es posible ver los chats de cualquier administrador, incluidos los de otras cuentas de administrador (propietario).
First Time Openwebui open Webui
Openwebui

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-18 19:44


NVD link : CVE-2024-7040

Mitre link : CVE-2024-7040

CVE.ORG link : CVE-2024-7040


JSON object : View

Products Affected

openwebui

  • open_webui
CWE
CWE-284

Improper Access Control