Open WebUIGHSA-c7fq-p62p-wvpc
Open WebUI Has Improper Access Control Leading to Arbitrary Prompt Read
Medium4.3CVE-2024-7045 · Published Mar 20, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| open-webui PyPI | <= 0.3.8 | No fix yet |
Details and references
In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompts. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/prompts/ interface to retrieve all prompt information created by the admin, which includes the ID values. Subsequently, the attacker can exploit the /api/v1/prompts/command/{command_id} interface to obtain arbitrary prompt information.
More Open WebUI advisories
All Open WebUI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-12537High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-12534High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI has vulnerable dependency on starlette via fastapi GHSA-w466-2wfc-8g58High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload CVE-2024-7044Medium6.8no fix yet | Medium6.8 | No fix yet |
| Mar 202025 | Open WebUI Allows Arbitrary File Reading and Deletion CVE-2024-7043High8.1no fix yet | High8.1 | No fix yet |
| Mar 202025 | Open WebUI Uncontrolled Resource Consumption vulnerability CVE-2024-7036High7.5no fix yet | High7.5 | No fix yet |