PT-2025-12211 · Unknown · Open-Webui

Published

2025-03-20

·

Updated

2025-03-27

·

CVE-2024-8053

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions open-webui/open-webui version v0.3.10
Description The api/v1/utils/pdf endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This issue can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.
Recommendations For version v0.3.10, consider implementing authentication mechanisms for the api/v1/utils/pdf endpoint to prevent unauthorized access. As a temporary workaround, restrict access to this endpoint to minimize the risk of exploitation. Avoid using the endpoint for generating PDFs without proper verification until a fix is available.

Exploit

Fix

DoS

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8053
GHSA-9VF8-XGWM-97R8

Affected Products

Open-Webui