THREAT OPS › Threat News › [GHSA] GHSA-3vf6-64vr-3g56 (low) — Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
[GHSA] GHSA-3vf6-64vr-3g56 (low) — Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
GHSA-3vf6-64vr-3g56 Severity: low CVE: CVE-2026-70483
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
## Summary `DELETE /api/v1/chats/{id}` cancelled a chat's in-flight tasks before it checked whether the caller was allowed to delete that chat. Any authenticated user who knew another user's chat id could therefore abort that user's runni
Indicators of compromise
- CVE-2026-70483cve
Original source: https://github.com/advisories/GHSA-3vf6-64vr-3g56