[GH-ISSUE #7561] CVE-2024-33663 with python-jose requirement vulnerability #14793

Closed
opened 2026-04-19 21:04:14 -05:00 by GiteaMirror · 3 comments
Owner

Originally created by @dmvieira on GitHub (Dec 2, 2024).
Original GitHub issue: https://github.com/open-webui/open-webui/issues/7561

Summary

This is a critical severity security issue opened here.

Details

Latest version of openwebui is using python-jose 3.3.0

PoC

look at requirements.txt or pyproject.toml

Impact

Security scans are blocking it

Originally created by @dmvieira on GitHub (Dec 2, 2024). Original GitHub issue: https://github.com/open-webui/open-webui/issues/7561 ### Summary This is a [critical severity security](https://vuldb.com/?id.262059) issue [opened here](https://github.com/mpdavis/python-jose/issues/346). ### Details Latest version of openwebui is using python-jose 3.3.0 ### PoC look at requirements.txt or pyproject.toml ### Impact Security scans are blocking it
Author
Owner

@tjbck commented on GitHub (Dec 2, 2024):

I'm pretty sure it's not being used anywhere in the codebase. Confirmation wanted here!

<!-- gh-comment-id:2512632141 --> @tjbck commented on GitHub (Dec 2, 2024): I'm pretty sure it's not being used anywhere in the codebase. Confirmation wanted here!
Author
Owner

@dmvieira commented on GitHub (Dec 2, 2024):

it's here: https://github.com/search?q=repo%3Aopen-webui%2Fopen-webui%20python-jose&type=code

<!-- gh-comment-id:2512669149 --> @dmvieira commented on GitHub (Dec 2, 2024): it's here: https://github.com/search?q=repo%3Aopen-webui%2Fopen-webui%20python-jose&type=code
Author
Owner

@tjbck commented on GitHub (Dec 2, 2024):

Yes it's in the requirements, but I believe it's not being used. Confirmation wanted here.

<!-- gh-comment-id:2512687221 --> @tjbck commented on GitHub (Dec 2, 2024): Yes it's in the requirements, but I believe it's not being used. Confirmation wanted here.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/open-webui#14793