VDB

CVE-2024-7959

CVE-2024-7959 PUBLISHED CVSS 7.699999809265137 HIGH

The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.

EPSS 0.51% · 66.9th percentile

Risk Scores

CVSS v3.0
7.699999809265137
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
0.51%
66.9th percentile

Affected Products

VendorProductVersions
openwebuiopen_webui0.3.8
open-webuiopen-webui/open-webui*
PyPIopen-webui0

Timeline

  • Mar 20, 2025 CVE Published
  • Mar 20, 2025 EPSS Score
  • Mar 21, 2025 CVE Updated
  • Mar 26, 2025 Coalition ESS Score
  • Apr 2, 2025 EPSS Score
  • Apr 16, 2025 EPSS Score
  • Apr 28, 2025 Coalition ESS Score
  • Apr 29, 2025 EPSS Score
  • May 12, 2025 EPSS Score
  • May 12, 2025 Coalition ESS Score
  • May 25, 2025 EPSS Score
  • Jun 3, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›