Executive brief
Open WebUI is an open-source web interface used to interact with AI/chat models. A previously reported issue suggested that an admin-only settings feature could leak file existence information through error messages, potentially letting an attacker infer file names or directory structure. However, this report has been officially withdrawn as not a genuine security vulnerability, so no real-world business risk or required action is associated with it.
Technical details
The original report (CWE-200 / CWE-209) claimed that the embedding model path update feature in Open WebUI's admin settings (backend/apps/rag/main.py, around line 199) returned different error messages depending on whether a specified file path existed, enabling an attacker with high privileges to enumerate file names and potentially traverse directories via oracle-style responses. The reported CVSS v3 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N, score 2.7) indicates it required high privileges (admin access) and had low confidentiality impact only. GitHub subsequently withdrew this advisory, stating it does not describe a valid vulnerability, meaning the behavior was likely intended or not exploitable as a security flaw. No patched version was listed since no fix was necessary. Affected package: pip package "open-webui" version <= 0.3.8.
Affected products
- open-webui open-webui <= 0.3.8
Timeline
- 2024-10-09: disclosed: Advisory published to GitHub Advisory Database
- 2026-09-02: other: Advisory withdrawn as not a valid vulnerability