CVE-2024-7033

Source
https://cve.org/CVERecord?id=CVE-2024-7033
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7033.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7033
Aliases
Published
2025-03-20T10:09:54.529Z
Modified
2026-07-22T20:18:46.256131972Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Arbitrary File Write in open-webui/open-webui
Details

In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write files to arbitrary locations on the server's filesystem. This can result in overwriting critical system or application files, causing denial of service, or potentially achieving remote code execution (RCE). RCE can allow an attacker to execute malicious code with the privileges of the user running the application, leading to a full system compromise.

Database specific
{
    "cna_assigner": "@huntr_ai",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7033.json",
    "cwe_ids": [
        "CWE-29"
    ]
}
References

Affected packages

Git / github.com/open-webui/open-webui

Affected ranges

Type
GIT
Repo
https://github.com/open-webui/open-webui
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.3.8"
        },
        {
            "last_affected": "0.3.8"
        }
    ],
    "cpe": "cpe:2.3:a:openwebui:open_webui:0.3.8:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

0.*
0.3.8
v0.*
v0.3.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7033.json"