PT-2025-12176 · Unknown · Open-Webui/Open-Webui
Published
2025-03-20
·
Updated
2025-07-18
·
CVE-2024-7036
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
open-webui/open-webui version 0.3.8
Description
A vulnerability allows an unauthenticated attacker to sign up with excessively large text in the
name field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions. The issue can also be exploited by authenticated users with low privileges, leading to the same unresponsive state in the Admin panel.Recommendations
For open-webui/open-webui version 0.3.8, consider restricting the length of the
name field to prevent excessively large input from causing the Admin panel to become unresponsive. As a temporary workaround, limit user sign-ups or manually monitor and manage user accounts to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open-Webui/Open-Webui