Back to Database
Status published
Medium
CVE-2024-30256
Open WebUI vulnerable to server-side request forgery in utils.py
Vulnerability Description
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-30256
Credits & Attribution
No credits recorded in the NVD database.
References
More from open-webui
View All →CVE-2025-65959
Open WebUI vulnerable to Stored DOM XSS via Note 'Download PDF'
High
8.7
CVE-2025-65958
Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
High
8.5
CVE-2025-64496
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
7.3
CVE-2025-64495
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
8.7
CVE-2025-46719
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
Medium
5.4
Affected Vendor
open-webui
View all reports →Affected Software
open-webui
Vulnerable Versions:
< 0.1.117
Timeline
Official Publish:
April 16th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N