THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jxc9-xmc4-gr23 (medium) — Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

[GHSA] GHSA-jxc9-xmc4-gr23 (medium) — Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

medgithub_advisoriesPublished 2026-08-04

GHSA-jxc9-xmc4-gr23 Severity: medium CVE: CVE-2026-70488

Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup

## Summary A user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jxc9-xmc4-gr23