FixVibe
Not automatically checkedunknown

Why Open WebUI CVE-2024-7959 Was Rejected

The SSRF advisory associated with Open WebUI's /openai/models endpoint was withdrawn. GitHub says the advisory does not describe a valid vulnerability, and NVD records that the CVE Numbering Authority rejected or withdrew CVE-2024-7959.

CVE-2024-7959GHSA-X757-HV69-JR45

Current advisory status

GitHub has withdrawn GHSA-x757-hv69-jr45, the advisory that associated CVE-2024-7959 with Open WebUI's /openai/models endpoint [S1]. GitHub now states that the advisory does not describe a valid vulnerability and retains the page only to preserve historical references [S1].

NVD marks CVE-2024-7959 as rejected and says the CVE Numbering Authority rejected or withdrew the identifier [S2]. NVD's change history shows that the earlier affected-product mapping, CVSS data, CWE classification, and exploit reference were removed when the record was rejected [S2].

What changed

The original report alleged that Open WebUI 0.3.8 allowed a user-controlled OpenAI API URL to direct a server-side request [S1]. That allegation remains visible only as historical text; it is not the current advisory conclusion [S1].

GitHub withdrew the reviewed advisory on September 2, 2026 [S1]. NVD records the earlier CVE rejection by the issuing authority on July 16, 2026 [S2]. Neither current record provides a supported affected-version range, patched version, CVSS score, or CWE mapping for a valid vulnerability [S1] [S2].

What maintainers should do

If a dependency or vulnerability scanner still reports CVE-2024-7959 for Open WebUI, confirm that its advisory feed has ingested the rejection before changing application code or package versions [S1] [S2]. A temporary suppression can cite the withdrawn GHSA or rejected CVE and should be reviewed if an authoritative source changes the record again [S1] [S2].

The withdrawn advisory and rejected CVE do not establish an affected version, a fix release, or a current Open WebUI vulnerability [S1] [S2].

Why FixVibe will not check this automatically

FixVibe will not publish a vulnerability finding for Open WebUI under CVE-2024-7959 because the authoritative records now say the report is not a valid vulnerability [S1] [S2]. Reproducing the obsolete callback proposal would create an unsafe and misleading result rather than target-specific evidence.

This withdrawn record will remain a research note and will not be used as a shipped detector [S1] [S2].

Why Open WebUI CVE-2024-7959 Was Rejected β€” FixVibe research Β· FixVibe