PT-2025-12178 · Unknown · Open-Webui

Published

2025-03-20

·

Updated

2025-07-18

·

CVE-2024-7040

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions open-webui/open-webui version v0.3.8
Description The issue is related to improper access control. Administrators are supposed to view only the chats of non-admin members on the frontend admin page. However, it is possible to view the chats of any administrator by modifying the user id parameter. This allows access to the chats of other admin, including owner accounts.
Recommendations For version v0.3.8, as a temporary workaround, consider restricting access to the user id parameter in the affected API endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-7040

Affected Products

Open-Webui