THREAT OPS › Threat News › [GHSA] GHSA-mj5r-jf49-m3w7 (medium) — Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
[GHSA] GHSA-mj5r-jf49-m3w7 (medium) — Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
GHSA-mj5r-jf49-m3w7 Severity: medium CVE: CVE-2026-70481
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
## Summary On standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order
Indicators of compromise
- CVE-2026-70481cve
Original source: https://github.com/advisories/GHSA-mj5r-jf49-m3w7