Skip to content
Open WebUIGHSA-9vf8-xgwm-97r8

Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint

High7.5CVE-2024-8053 · Published Mar 20, 2025 · updated Jul 7, 2026

In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.

GitHub advisory

Affected versions

PackageAffectedFixed in
open-webui
PyPI
<= 0.3.10No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287, CWE-306
Also known as
CVE-2024-8053, PYSEC-2026-1725

More Open WebUI advisories

All Open WebUI

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.