We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-7806

Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webui



Description

A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the SameSite attribute set to lax for authentication and lacks CSRF tokens. This allows an attacker to craft a malicious HTML that, when accessed by a victim, can modify the Python code of an existing pipeline and execute arbitrary code with the victim's privileges.

Reserved 2024-08-14 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


HIGH: 8.0CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-352 Cross-Site Request Forgery (CSRF)

Product status

Any version
affected

References

huntr.com/bounties/9350a68d-5f33-4b3d-988b-81e778160ab8

cve.org (CVE-2024-7806)

nvd.nist.gov (CVE-2024-7806)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-7806

Support options

Helpdesk Chat, Email, Knowledgebase
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011
MonTueWedThuFriSatSun
311234567891011121314151617181920212223242526272829301234567891011