CVE-2024-7806: Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
8
CVSS Score
3.0
Basic Information
CVE ID
GHSA ID
EPSS Score
0.47861%
CWE
Published
3/20/2025
Updated
3/21/2025
KEV Status
No
Technology
Python
Technical Details
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| open-webui | pip |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from improper cookie security attributes in authentication flows. The functions listed all handled session cookie creation/modification and were missing critical 'SameSite=strict' and 'Secure' attributes before the patch (CVE-2024-7806). This allowed cross-origin request forgery as the lax SameSite policy permits some cross-site requests, and missing Secure flag enables transmission over HTTP. The GitHub commit 7e253df explicitly adds these security attributes to these specific authentication functions, confirming they were the vulnerable points.