{"id":"CVE-2024-7041","aliases":["GHSA-xcvc-5hgv-phqg","PYSEC-2026-1744"],"url":"https://o3.security/vulnerability/CVE-2024-7041","summary":"IDOR in open-webui/open-webui","details":"An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization.","published":"2024-10-09T19:57:41.184Z","modified":"2026-08-12T03:51:14.720419169Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"open-webui","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://huntr.com/bounties/6855227f-1237-47b8-8d37-29aad7ddec3a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7041.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7041"},{"type":"PACKAGE","url":"https://github.com/open-webui/open-webui"},{"type":"WEB","url":"https://github.com/open-webui/open-webui/blob/main/backend/apps/webui/routers/memories.py#L71"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.720419169Z"}}