Impact
The sync cleanup endpoint in Open WebUI versions 0.9.6 through 0.10.x, before the 0.11.0 fix, authorizes a user to write to any knowledge base using the URL but fails to verify that the directory and file IDs supplied belong to that knowledge base. Consequently, a user with write permissions on one knowledge base can delete directories and remove file embeddings from another, causing documents to disappear from retrieval results and breaking chat‑with‑file functionality. The flaw does not leak content but undermines the integrity and availability of the target knowledge base.
Affected Systems
Open WebUI 0.9.6–0.10.x (up through 0.10.x). The vulnerability was addressed in the 0.11.0 release.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered moderate. Attack requires authenticated access and write permissions, so exploitation is limited to users who already have sufficient privileges. The EPSS score is not available and the flaw is not listed in CISA's KEV catalog, indicating a lower likelihood of widespread exploitation, but the impact on data availability can be significant in multi‑tenant deployments.
OpenCVE Enrichment
Github GHSA