Skip to content
Open WebUIGHSA-xcvc-5hgv-phqg

open-webui Insecure Direct Object Reference (IDOR) vulnerability

Medium6.5CVE-2024-7041 · Published Oct 9, 2024 · updated Jul 7, 2026

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.

GitHub advisory

Affected versions

PackageAffectedFixed in
open-webui
PyPI
<= 0.3.8No fix yet
Details and references

More Open WebUI advisories

All Open WebUI
Advisory
Open WebUI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025
Open WebUI has vulnerable dependency on starlette via fastapi
High7.5Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025
open-webui allows writing and deleting arbitrary files
Medium6.5Oct 9, 2024
Open WebUI Stored Cross-Site Scripting Vulnerability
Medium6.1Aug 8, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.