Skip to content

Withdraw GHSA-mq92-jr35-ffpc: source CVE-2024-7038 rejected by issuing CNA#8765

Open
Classic298 wants to merge 1 commit into
github:Classic298/advisory-improvement-8765from
Classic298:withdraw-GHSA-mq92-jr35-ffpc
Open

Withdraw GHSA-mq92-jr35-ffpc: source CVE-2024-7038 rejected by issuing CNA#8765
Classic298 wants to merge 1 commit into
github:Classic298/advisory-improvement-8765from
Classic298:withdraw-GHSA-mq92-jr35-ffpc

Conversation

@Classic298

Copy link
Copy Markdown

I am a maintainer of the affected project (open-webui/open-webui). This advisory's source CVE, CVE-2024-7038, has been rejected by its issuing CNA (Protect AI / huntr), and both authoritative CVE sources reflect it:

Since the underlying CVE has been rescinded, this GitHub-reviewed mirror should be withdrawn. It currently carries affected range <= 0.3.8 with no patched version, so it produces perpetual unfixable false positives in Dependabot and downstream scanners. There is no fixed version to assign; the correct correction is withdrawal.

This change adds the OSV withdrawn timestamp. For the record, as maintainer: the cited path-load sink is reached only via admin-only (get_admin_user) configuration endpoints, and a verbose exception string revealing whether a local path exists, shown to the admin who operates that host, crosses no security boundary.

@github-actions
github-actions Bot changed the base branch from main to Classic298/advisory-improvement-8765 July 22, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant