THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mj5r-jf49-m3w7 (medium) — Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

[GHSA] GHSA-mj5r-jf49-m3w7 (medium) — Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

medgithub_advisoriesPublished 2026-08-04

GHSA-mj5r-jf49-m3w7 Severity: medium CVE: CVE-2026-70481

Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages

## Summary On standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mj5r-jf49-m3w7