# Askar Labs

Source: https://docs.openwebui.com/security/supply-chain-security/vulnerability-databases/askar-labs

|  |  |
| --- | --- |
| Product | Askar Labs CVE Database |
| Records still shown as active | 9, every withdrawn identifier against Open WebUI |
| First contacted | 2026-08-08 |
| Channels tried | hello@askarlabs.com |
| Status | Awaiting response |

---

## Records

Every CVE withdrawn against Open WebUI still has a live entry, carrying the original description, the original severity and no rejection marker. Each identifier below is in the `REJECTED` state at [cve.org](https://www.cve.org) and at NVD:

| Identifier | Withdrawn by | Rejected since | Still live on Askar Labs | Our assessment |
| --- | --- | --- | --- | --- |
| CVE-2024-7033 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2024-7034 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2024-7038 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2024-7039 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2024-7040 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2024-7959 | huntr / Protect AI | 2026-07-16 | askarlabs.com | Disposition |
| CVE-2025-15603 | VulDB | 2026-06-18 | askarlabs.com | Disposition |
| CVE-2025-29446 | MITRE | 2026-06-29 | askarlabs.com | Disposition |
| CVE-2025-63391 | MITRE | 2026-06-29 | askarlabs.com | Disposition |

### The entries say the current release is affected

This goes past a stale severity. It is an affirmative claim about which versions of Open WebUI carry the defect, published on records that no longer exist:

| Identifier | Affected versions, as published | Reality |
| --- | --- | --- |
| CVE-2024-7033 | "≥ unspecified and ≤ latest" | Withdrawn. No version is affected. |
| CVE-2024-7040 | "≥ unspecified and ≤ latest" | Withdrawn. No version is affected. |
| CVE-2025-29446 | "All versions" | Withdrawn. No version is affected. |
| CVE-2025-63391 | "All versions" | Withdrawn. No version is affected. |

An upper bound of "latest" is not a bound at all. It tells a reader that whatever release of Open WebUI they are running right now, including one shipped today, is vulnerable. The descriptions on these same entries name specific old versions. The CVE-2024-7033 entry describes version 0.3.8, and the CVE-2025-29446 entry describes v0.5.16. Neither description claims anything about later releases, and both identifiers have since been withdrawn entirely, so the version range and the text beside it disagree on the same page.

An operator checking whether their deployment is exposed gets the worst possible answer here: yes, always, on a finding that does not exist.

### Two of them do not even name the product

On [CVE-2025-29446](https://askarlabs.com/cve/CVE-2025-29446/) and [CVE-2025-63391](https://askarlabs.com/cve/CVE-2025-63391/) the Vendor field reads "N/A" and the Product field reads "n/a", while the Affected field reads "All versions" and the description names Open WebUI in prose.

An entry that cannot say which product it applies to is nonetheless asserting that every version of it is affected.

### Records last updated before the withdrawal

| Identifier | Last updated, as shown | Withdrawn |
| --- | --- | --- |
| CVE-2024-7033 | 2025-03-20, the day it was published | 2026-07-16 |
| CVE-2024-7040 | 2025-10-15 | 2026-07-16 |
| CVE-2025-29446 | 2025-05-12 | 2026-06-29 |
| CVE-2025-63391 | 2026-01-22 | 2026-06-29 |

CVE-2024-7033 has not been touched since the day it was published, nearly seventeen months ago. It still carries the full original description, ending with the claim that the issue can be escalated to remote code execution and "a full system compromise", and a CVSS of 6.5 Medium.

---

## Contact log

| Date | Channel | Outcome |
| --- | --- | --- |
| 2026-08-08 | hello@askarlabs.com | Awaiting response |

---

## See also

- [Rejected CVEs in Vulnerability Databases](/security/supply-chain-security/vulnerability-databases/) — the overview and how to verify any record yourself.
- [Vendor Dispositions](/security/vendor-dispositions) — our assessment of each identifier listed above.
