CVE-2024-7037: Arbitrary File Write/Delete Leading to RCE in open-webui/open-webui
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHEDIR. This vulnerability allows attackers to overwrite and delete system files, potentially leading to remote code execution.
Other sources
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7037?
CVE-2024-7037 has a high severity rating due to its potential impact on system security through arbitrary file writes and deletes.
How do I fix CVE-2024-7037?
To fix CVE-2024-7037, update open-webui to version 0.3.9 or later, which addresses this vulnerability.
What versions are affected by CVE-2024-7037?
CVE-2024-7037 affects open-webui versions up to and including 0.3.8.
What type of vulnerability is CVE-2024-7037?
CVE-2024-7037 is an arbitrary file write and delete vulnerability due to unsanitized input.
Who is impacted by CVE-2024-7037?
Users of open-webui version 0.3.8 and earlier are impacted by CVE-2024-7037, potentially allowing unauthorized file access.