A AegiFlow
MEDIUMCVSS 4.3EPSS 0.2%

CVE-2026-70488

CVE-2026-70488 updated by NVD

Published
2026-08-04
Modified
2026-09-20
EPSS percentile
12%
Sources
github-advisory, nvd

Summary

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request body without checking that those objects belonged to that knowledge base. A user with write access to one knowledge base could delete directories and remove file embeddings from another knowledge base, causing documents to drop out of retrieval results and breaking chat-with-file for targeted documents without disclosing contents. This issue is fixed in 0.11.0.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIopen-webui0.11.0

Remediation: Upgrade to 0.11.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.