VDB
CVE-2024-7959
CVE-2024-7959
PUBLISHED
CVSS 7.699999809265137 HIGH
The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.
EPSS 0.51% · 66.9th percentile
Risk Scores
CVSS v3.0
7.699999809265137
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
0.51%
66.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openwebui | open_webui | 0.3.8 |
| open-webui | open-webui/open-webui | * |
| PyPI | open-webui | 0 |
Timeline
- Mar 20, 2025 CVE Published
- Mar 20, 2025 EPSS Score
- Mar 21, 2025 CVE Updated
- Mar 26, 2025 Coalition ESS Score
- Apr 2, 2025 EPSS Score
- Apr 16, 2025 EPSS Score
- Apr 28, 2025 Coalition ESS Score
- Apr 29, 2025 EPSS Score
- May 12, 2025 EPSS Score
- May 12, 2025 Coalition ESS Score
- May 25, 2025 EPSS Score
- Jun 3, 2025 Coalition ESS Score