Junglewise Threat Intelligence

CVE-2024-7033: Open WebUI path traversal in download_model endpoint (withdrawn)

CVE-2024-7033 · Severity: medium · CVSS 6.5 · Published 2025-03-20

Technologies: open-webui (PyPI). Vendors: PyPI.

Executive brief

This advisory describes a reported flaw in Open WebUI, an open-source interface used to interact with AI/chat models, where a model download feature was thought to allow attackers to write files to arbitrary locations on the server, potentially crashing the application or leading to full system compromise on Windows deployments. However, the issuing authority has since withdrawn this advisory, stating it does not describe a valid vulnerability. Organizations using Open WebUI do not need to take action based on this specific report, though staying current with official security advisories is still recommended.

Technical details

The original report described a path traversal (CWE-29) issue in the download_model endpoint of open-webui/open-webui version <= 0.3.8, where the application allegedly did not properly sanitize file path input on Windows, permitting an attacker to control the destination path of a written file and potentially overwrite arbitrary files, leading to denial of service or remote code execution. Reported CVSS was 3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H (6.5, medium), requiring high privileges but no user interaction. No patched version was ever listed. This GitHub Security Advisory (GHSA-3p9q-7w63-3f8q / CVE-2024-7033) has since been formally withdrawn by GitHub as not describing a valid vulnerability, so the technical claims should not be treated as confirmed or actionable; the entry is retained only to preserve external references (e.g., NVD, huntr bounty link).

Affected products

  • open-webui open-webui <= 0.3.8 (originally reported; advisory later withdrawn)

Timeline

  • 2025-03-20: disclosed: Advisory published to GitHub Advisory Database
  • 2025-03-21: advisory: GitHub reviewed the advisory
  • 2026-09-02: other: Advisory withdrawn as not describing a valid vulnerability

References

Related threats