RULE(RULE ID:338758)

Rule General Information
Release Date: 2025-03-26
Rule Name: Open WebUI Directory Traversal Vulnerability (CVE-2024-7037)
Severity:
CVE ID:
Rule Protection Details
Description: Open WebUI is an open-source, scalable, feature rich, and user-friendly self hosted WebUI. The Open WebUI v0.3.8 version has a path traversal vulnerability, which is vulnerable to arbitrary file write and delete attacks, allowing attackers to overwrite and delete system files, resulting in remote code execution.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Refer to the announcement or patch by the vendor: https://github.com/open-webui/open-webui/releases/tag/v0.3.32