GHSA-p5vx-9hj8-cf4h

Suggest an improvement
Source
https://github.com/advisories/GHSA-p5vx-9hj8-cf4h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p5vx-9hj8-cf4h
Aliases
Published
2025-03-20T12:32:46Z
Modified
2026-07-07T17:56:12Z
Severity
  • 6.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L CVSS Calculator
Summary
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF)
Details

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious site or through top-level navigation. The affected endpoints include /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads. This impacts both the availability and integrity of the application.

Database specific
{
    "cwe_ids": [
        "CWE-352"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-21T22:11:41Z",
    "nvd_published_at": "2025-03-20T10:15:35Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / open-webui

Package

Name
open-webui
View open source insights on deps.dev
Purl
pkg:pypi/open-webui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.3.8

Affected versions

0.*
0.1.124
0.1.125
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json"