CVE-2024-7037 Blast Radius

✕ WITHDRAWN — HISTORICAL DATAIn version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fil