Impact
The vulnerability allows any user who has write permission to a standard channel to edit or delete messages sent by other members. Because the message update and delete handlers do not verify authorship, an ordinary participant can replace or permanently remove another user's posts. This bypasses the proper access controls that otherwise restrict these actions to the original author, thereby compromising message integrity.
Affected Systems
Open WebUI (open-webui) deployments using releases from 0.5.0 up to but not including 0.11.0 are affected. Any self‑hosted instance of the platform running a pre‑0.11.0 version is vulnerable to this flaw.
Risk and Exploitability
The CVSS score of 5.4 signals a medium severity issue focused on message integrity. The EPSS score is not available, yet the flaw can be exploited by any channel member with write rights, which is a common scenario in many teams. The vulnerability is not listed in the CISA KEV catalog. Attackers could deface conversations or erase important content with ease, making an immediate patch highly advisable.
OpenCVE Enrichment
Github GHSA