THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3cg5-48j3-v4gv (high) — Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

[GHSA] GHSA-3cg5-48j3-v4gv (high) — Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

medgithub_advisoriesPublished 2026-08-04

GHSA-3cg5-48j3-v4gv Severity: high CVE: CVE-2026-70494

Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder

## Summary A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3cg5-48j3-v4gv